DNSUnlockerの広告等々・・・
数日前から件名にもあるように以下の現象で困っています。
・DNSUnlocker関連の広告が表示される。
・webページ内の一部の文字が青くなりマウスカーソルを合わせるとDNSUnlocker関連の小さな広告のようなものが出る。(クリックすると飛ばされそうなので試してはいません)
・クリックしたリンク先とは違うページに飛ばされる。
・リンク先が表示されたかと思えばそこからさらに別のページに飛ばされる。

勝手に別のページに飛ばされた場合タブの文字が「n162adserv.com」「Direct」などに切り替わり、
最終的には「Reimage Repair」というセキュリティのページ等の「いかにも胡散臭い」ところに飛ばされてしまいます。
またyoutubeの動画を見ようとすると「Empty」というページに飛ばされたりします。

現象発生後にWindows7からWindows10にアップデートしてしまいましたが、
今からでも対処可能でしょうか?
以下Logですよろしくお願いします。




Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 23:43:02, on 2015/09/01
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Users\【ユーザー名】\Downloads\HijackThis.exe

F2 - REG:system.ini: UserInit=
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{857478e4-9b24-42e0-a39e-a800a9c0b3d5}: NameServer = 82.163.143.169,82.163.142.171
O17 - HKLM\System\CCS\Services\Tcpip\..\{cfc30fb7-e730-4f6c-ac70-34c05625133f}: NameServer = 82.163.143.169,82.163.142.171
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: Tor Win32 Service (tor) - Unknown owner - C:\Program Files (x86)\Tor\tor.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11041 bytes
----------------------------------------------------------------


Adobe AIR Adobe Systems Incorporated 2015/08/28 4.0.0.1390
Adobe Flash Player 10 Plugin Adobe Systems Incorporated 2015/08/28 10.0.32.18
Adobe Reader X (10.1.15) MUI Adobe Systems Incorporated 2015/08/28 363 MB 10.1.15
Asmedia ASM104x USB 3.0 Host Controller Driver Asmedia Technology 2012/04/17 2.27 MB 1.12.5.0
ASUS AI Recovery ASUS 2012/10/13 11.5 MB 1.0.27
ASUS LifeFrame3 ASUS 2012/04/17 30.2 MB 3.0.22
ASUS Live Update ASUS 2012/04/17 3.97 MB 3.0.6
ASUS Power4Gear Hybrid ASUS 2012/04/17 13.2 MB 1.1.45
ASUS Secure Delete ASUS 2012/04/17 6.35 MB 1.00.0007
ASUS SmartLogon ASUS 2012/04/17 11.1 MB 1.0.0011
ASUS Splendid Video Enhancement Technology ASUS 2012/04/17 19.2 MB 1.02.0033
ASUS USB Charger Plus AsusTek Computer Inc. 2012/04/17 2.0.2
ASUS Virtual Camera asus 2012/04/17 3.13 MB 1.0.21
ASUS WebStorage eCareme Technologies, Inc. 2015/08/28 3.0.108.222
AsusScr_U_24_Series_ENG ASUS 2015/08/28 159 MB 1.0.0001
Atheros Client Installation Program Atheros 2012/04/17 7.0
ATK Package ASUS 2012/04/17 12.0 MB 1.0.0013
Bluetooth Win7 Suite (64) Atheros Communications 2012/04/17 59.4 MB 7.02.000.55
CCleaner Piriform 2015/09/01 5.09
CyberLink LabelPrint CyberLink Corp. 2012/04/17 49.8 MB 2.5.3624
CyberLink Media Suite CyberLink Corp. 2012/04/17 40.4 MB 8.0.2926
CyberLink Power2Go CyberLink Corp. 2012/04/17 223 MB 7.0.0.1126
Dotfuscator Software Services - Community Edition PreEmptive Solutions 2013/03/29 6.45 MB 5.0.2500.0
Dotfuscator Software Services - Community Edition - JPN PreEmptive Solutions 2012/05/30 3.07 MB 5.0.2300.0
ETDWare PS/2-X64 8.0.5.3_WHQL ELAN Microelectronic Corp. 2015/08/28 8.0.5.3
Fast Boot ASUS 2012/04/17 1.46 MB 1.0.10
Google Chrome Google Inc. 2012/03/02 39.0.2171.65
Google Toolbar for Internet Explorer Google Inc. 2015/08/28 7.5.6710.2136
InstantOn for NB ASUS 2012/04/17 4.27 MB 2.1.3
Intel Driver Update Utility Intel 2015/08/28 19.6 MB 2.2.0.2
Intel(R) Control Center Intel Corporation 2012/04/17 1.2.1.1007
Intel(R) Management Engine Components Intel Corporation 2012/04/18 7.0.0.1144
Intel(R) Processor Graphics Intel Corporation 2013/03/29 9.17.10.2932
Java 8 Update 60 Oracle Corporation 2015/08/28 20.6 MB 8.0.600.27
Lhaz ちとらソフト 2015/08/28 2.2.4
MetasequoiaLE R3.0 2015/08/28
Microsoft .NET Framework 4 Multi-Targeting Pack Microsoft Corporation 2012/05/30 83.4 MB 4.0.30319
Microsoft ASP.NET MVC 2 Microsoft Corporation 2014/10/16 482 KB 2.0.60926.0
Microsoft ASP.NET MVC 2 - JPN Microsoft Corporation 2012/05/30 25.0 KB 2.0.50331.0
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools Microsoft Corporation 2012/05/30 2.25 MB 2.0.50217.0
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - JPN Microsoft Corporation 2012/05/30 2.13 MB 2.0.50402.0
Microsoft DirectX 9.0 SDK Update (October 2004) Microsoft® Corporation 2012/05/30 337 MB 9.02.3900
Microsoft Help Viewer 1.1 Microsoft Corporation 2015/08/28 3.97 MB 1.1.40219
Microsoft Help Viewer 1.1 Language Pack - JPN Microsoft Corporation 2015/08/28 1.95 MB 1.1.40219
Microsoft Office Professional Plus 2010 Microsoft Corporation 2015/08/28 14.0.7015.1000
Microsoft Silverlight Microsoft Corporation 2015/08/13 348 MB 5.1.40728.0
Microsoft Silverlight 3 SDK - 日本語 Microsoft Corporation 2012/05/30 33.3 MB 3.0.40818.0
Microsoft Silverlight 4 SDK - 日本語 Microsoft Corporation 2013/03/29 53.1 MB 4.0.50826.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2012/03/02 1.69 MB 3.1.0000
Microsoft SQL Server 2008 (64-bit) Microsoft Corporation 2015/08/28
Microsoft SQL Server 2008 Browser Microsoft Corporation 2013/03/29 7.97 MB 10.3.5500.0
Microsoft SQL Server 2008 Native Client Microsoft Corporation 2013/03/29 7.07 MB 10.3.5500.0
Microsoft SQL Server 2008 R2 Transact-SQL 言語サービス Microsoft Corporation 2013/03/29 6.79 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 データ層アプリケーション フレームワーク Microsoft Corporation 2013/03/29 5.61 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 データ層アプリケーション プロジェクト Microsoft Corporation 2013/03/29 14.1 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 管理オブジェクト Microsoft Corporation 2013/03/29 14.4 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 管理オブジェクト (x64) Microsoft Corporation 2013/03/29 6.59 MB 10.50.1750.9
Microsoft SQL Server 2008 Setup Support Files Microsoft Corporation 2015/07/16 54.2 MB 10.3.5538.0
Microsoft SQL Server Compact 3.5 SP2 JPN Microsoft Corporation 2012/05/30 3.66 MB 3.5.8080.0
Microsoft SQL Server Compact 3.5 SP2 x64 JPN Microsoft Corporation 2012/05/30 4.78 MB 3.5.8080.0
Microsoft SQL Server Database Publishing Wizard 1.4 Microsoft Corporation 2012/05/30 10.1 MB 10.1.2512.8
Microsoft SQL Server System CLR Types Microsoft Corporation 2013/03/29 991 KB 10.50.1750.9
Microsoft SQL Server System CLR Types (x64) Microsoft Corporation 2013/03/29 870 KB 10.50.1750.9
Microsoft SQL Server VSS Writer Microsoft Corporation 2013/03/29 4.02 MB 10.3.5500.0
Microsoft Sync Framework Runtime v1.0 SP1 (x64) ja Microsoft Corporation 2012/05/30 1.06 MB 1.0.3010.0
Microsoft Sync Framework SDK v1.0 SP1 ja Microsoft Corporation 2012/05/30 30.1 MB 1.0.3010.0
Microsoft Sync Framework Services v1.0 SP1 (x64) ja Microsoft Corporation 2012/05/30 2.92 MB 1.0.3010.0
Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) ja Microsoft Corporation 2012/05/30 630 KB 2.0.3010.0
Microsoft Team Foundation Server 2010 オブジェクト モデル - 日本語 Microsoft Corporation 2015/08/28 10.0.40219
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2012/06/04 300 KB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/05/28 230 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2012/04/17 596 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 Microsoft Corporation 2012/05/30 599 KB 9.0.30729.4974
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2012/06/04 600 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319 Microsoft Corporation 2012/05/30 314 KB 10.0.30319
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/16 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 Microsoft Corporation 2013/03/29 20.5 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/16 11.1 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 Microsoft Corporation 2013/03/29 15.9 MB 10.0.40219
Microsoft Visual F# 2.0 Runtime Microsoft Corporation 2013/03/29 5.84 MB 10.0.40219
Microsoft Visual F# 2.0 Runtime Language Pack - 日本語 Microsoft Corporation 2012/05/30 1.34 MB 10.0.30319
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools Microsoft Corporation 2013/03/29 35.4 MB 10.0.40219
Microsoft Visual Studio 2010 Professional - 日本語 Microsoft Corporation 2015/08/28 10.0.30319
Microsoft Visual Studio 2010 Service Pack 1 Microsoft Corporation 2015/08/28 75.9 MB 10.0.40219
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Corporation 2015/08/28 10.0.50903
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語 Microsoft Corporation 2015/08/28 10.0.50903
Microsoft Visual Studio Macro Tools Microsoft Corporation 2015/08/28 9.0.30729
Microsoft Visual Studio Macro Tools - JPN Language Pack Microsoft Corporation 2015/08/28 9.0.30729
PowerWiz ASUS 2012/04/17 6.89 MB 1.0.3
Prominence 2015/08/28
Realtek Ethernet Controller Driver Realtek 2012/04/17 7.44.421.2011
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2015/08/28 6.0.1.7535
Realtek USB 2.0 Reader Driver Realtek Semiconductor Corp. 2012/04/17 6.1.7600.10008
Revo Uninstaller 1.95 VS Revo Group 2015/08/28 1.95
RGSS-RTP Standard Enterbrain 2013/04/27 1.03
RPGツクール2000 ランタイムパッケージ 2015/08/28
RPGツクールVX Enterbrain 2013/11/12 140 MB 1.03a
RPGツクールVX Ace RTP Enterbrain 2013/11/10 194 MB 1.00
RPGツクールVX RTP Enterbrain 2013/11/12 42.1 MB 1.02
RPGツクール2003 ランタイムパッケージ 2015/08/28
SceneSwitch ASUS 2012/04/17 2.22 MB 1.0.8
SlimDX Redistributable for .NET 2.0 (September 2011) SlimDX Group 2014/04/12 15.5 MB 2.0.12.43
SlimDX Runtime .NET 2.0 (January 2012) SlimDX Group 2014/04/12 17.2 MB 2.0.13.43
Sonic Focus Synopsys 2012/04/17 4.31 MB 1.0.0.4
Synaptics Pointing Device Driver Synaptics Incorporated 2015/08/28 46.4 MB 19.0.9.5
Unity Web Player Unity Technologies ApS 2015/08/28 12.0 MB
Visual Studio 2010 Prerequisites - English Microsoft Corporation 2013/03/29 23.2 MB 10.0.40219
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 JPN Microsoft Corporation 2012/05/30 11.2 MB 4.0.8080.0
WCF RIA Services V1.0 SP1 Microsoft Corporation 2013/03/29 12.3 MB 4.1.60114.0
Web Deployment Tool Microsoft Corporation 2012/05/30 3.10 MB 1.1.0618
Windows Live Essentials Microsoft Corporation 2012/03/02 15.4.3538.0513
WinFlash ASUS 2012/04/17 856 KB 2.31.1
Wireless Console 3 ASUS 2012/04/17 9.05 MB 3.0.21
インテル(R) ターボ・ブースト・テクノロジー・モニター 2.0 インテル 2012/04/17 13.2 MB 2.1.23.0
リモート接続用の Windows Live Mesh ActiveX コントロール (日本語) Microsoft Corporation 2012/03/02 5.57 MB 15.4.5722.2
  • ぐぬぬ
  • 2015/09/02 (Wed) 00:26:54
処置を開始しましょう
こんにちは、IVNOと申します。
現在本館、別館あわせて相談者多数のため、なかなか回答が追いついていなくて申し訳ありません。
表面上は特に問題点が見えないようになっているのも、最近のマルウェアの仕業ですね。
私もユ○ケル片手にがんばりますので、一緒にがんばって駆除していきましょう。

それでは作業準備を行いましょう。

まずはじめに連絡事項がございます。
相談いただいてから回答できるまでに、毎回1日かそれ以上かかる可能性もございます。
ご不便をおかけいたしますが、ご理解とご協力を賜りますよう、お願い申し上げます。
また、回答者側から「解決」と通達があるまで、駆除作業は続いております。
そのため、途中でPCの状況が良くなったかのように感じたからと言って、解決のご案内を待たずして作業を中断なされると、
高確率で再発しているのが現状で、再発時にこちらにお戻りになられる方が続出しております。
回答者から「解決」と「自衛策」の案内があるまでは、作業を続けるようにしてください。

それでは以下の説明を熟読し、順番に作業をお願いします。
既に準備した物もあるはずですが、一応説明を再度見ておいてください。

隠しファイルと拡張子を表示設定にしてください(やり方↓)
http://pasofaq.jp/windows/mycomputer/hiddenfile.htm
http://support.microsoft.com/kb/978449/ja

下記のツールをダウンロードして、基本の使い方を把握しておいてください。
ただし、配布サイトで他のソフトウェアをダウンロードしろと勧めてくるような広告も出てくる可能性がありますが、
それらは絶対にクリックしないでください。

GeekUninstaller(通称:GU)
ダウンロード
http://www.geekuninstaller.com/geek.zip
ファイル直リンクです。zipファイルですので使用前に展開してください。
削除の際はそのままごみ箱に処分してください。
解説
http://www.gigafree.net/system/install/geekuninstaller.html

「CCleaner」(通称:CC)
説明↓
http://www.gigafree.net/system/clean/ccleaner.html
http://note.chiebukuro.yahoo.co.jp/detail/n178757
ダウンロード↓
http://www.piriform.com/ccleaner/download/standard
最新バージョンをダウンロードするようにしましょう。
なお、インストール時におまけのアプリも勧めてくることがありますが、それらはチェック外してインストールは避けてください。
削除の際はGUなどでアンインストールしてください。

ここで重要な注意です。
CCは本来は高い性能を持つメンテナンスソフトですが、間違った使い方すると
【操作次第ではWindowsが動作しなくなる可能性もある】
ので、ここでは解析ツールとしてのみ使います。
説明をしっかり読んで、こちらが指示した以外の操作はしないようにしてください。

準備できたら作業を開始しましょう。

Adobe Readerが更新されていませんので、最新版を用意しましょう。

Adobe Acrobat Reader DC
https://get.adobe.com/jp/reader/
オプションのプログラムの部分のチェックは必ず外してからダウンロードしてください。

以降の駆除作業でトラブルが発生しても直ちに復旧できるよう、システムの復元ポイントを手動で作成しましょう。
http://windows.microsoft.com/ja-jp/windows7/create-a-restore-point
しかし、システムの復元はPCにかなりのダメージを与えますので、できれば使わないほうが望ましいです。
システムの復元が必要のない、慎重な作業を心がけましょう。

PCをセーフモードで起動してください(やり方↓)
http://www.pc-master.jp/sousa/s-safemode.html
Windows 8または8.1の方は以下を参考になされてください。
http://121ware.com/qasearch/1007/app/servlet/relatedqa?QID=015917
HJTを起動させ、スキャンを行ってください。
スキャン結果が表示されましたら、以下の項目にチェックを入れてください。
ただし、特にHJTでの作業は一歩間違えれば簡単にPCが起動しなくなるため、
こちらが指示した以外のものは絶対にチェックを入れないでください。

O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O23 - Service: Tor Win32 Service (tor) - Unknown owner - C:\Program Files (x86)\Tor\tor.exe

必要な項目すべてにチェックが入りましたら、Fix checkedをクリックしてください。
上記のFixが完了したらHJTを終了させてください。
Windowsインストーラーがどうとかの表示が出た場合はPCを通常モードで再起動し、
その状態で改めて該当ソフトウェアのみをアンインストールしてください。
通常モードとセーフモードを使い分けながらご案内しているすべてのソフトウェアの削除が完了するまで続けてください。
ご案内していたすべてのソフトウェアの削除が完了しましたら、
キーボードの左Ctrlと左Altの間にあるスタートボタンを押しながらRボタンを押します。
ファイル名を指定して実行と言うものが起動しますので、そちらに半角英数で以下を入力してください。

cleanmgr

入力が完了しましたらエンターキーを押してください。
C:ドライブを選択してOKを押します。
スキャンが開始されますので完了するまでお待ちください。
スキャンが完了すると一覧が表示されますので、すべてにチェックを入れてOKを押してください。
ただし、OKを押すとごみ箱の中身を含めてすべて削除されますので、
ごみ箱の中に必要なファイルが入っている場合はご注意ください。

処置が完了しましたらPCを通常モードで再起動させてください。
起動したら、「ツール」→「スタートアップ」→「Windows」タブを開いてください。
そこで右下の「テキストとして保存」を押すと、表示の内容がログとして保存できますので、
デスクトップ等、分かりやすい場所に最新のログのみ保存しておきましょう。
続いて「InternetExplorer」タブのログ、導入されておられるのであれば「Firefox」タブ、
同じく導入されておられるのであれば「Google Chrome」タブ、そして「スケジュールされたタスク」タブのログを取得してください。
ただし、「コンテキストメニュー」のログは取得していただく必要がございません。
CCの各ログを取得されましたら、CCは終了させて問題ありません。
取得したCCの各ログを返信欄に貼り付けていただき、ご報告をお願いいたします。
上記ログを確認後、次の作業内容をご案内いたします。
  • IVNO
  • MAIL
  • 2015/09/02 (Wed) 12:08:31
Re: DNSUnlockerの広告等々・・・
IVNOさん、返信ありがとうございます!

返答が遅れてしまい申し訳ありません。
早速ですが以下ログです。
改めてよろしくお願いします。

windows-------------------------------------------------------------------------------
有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run OneDrive Microsoft Corporation "C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
有効 HKCU:Run swg Google Inc. "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
無効 HKLM:Run Adobe Reader Speed Launcher "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
無効 HKLM:Run ASUS Screen Saver Protector ASUS C:\Windows\AsScrPro.exe
有効 HKLM:Run ASUSPRP ASUSTek Computer Inc. "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
有効 HKLM:Run ASUSWebStorage ecareme C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
有効 HKLM:Run AthBtTray Atheros Commnucations "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
有効 HKLM:Run AtherosBtStack "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
有効 HKLM:Run ATKMEDIA ASUS C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
有効 HKLM:Run ATKOSD2 ASUS C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
有効 HKLM:Run BCSSync Microsoft Corporation "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
無効 HKLM:Run CLMLServer CyberLink "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
有効 HKLM:Run ETDCtrl %ProgramFiles%\Elantech\ETDCtrl.exe
有効 HKLM:Run HControlUser ASUS C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
有効 HKLM:Run HotKeysCmds Intel Corporation "C:\WINDOWS\system32\hkcmd.exe"
有効 HKLM:Run IgfxTray Intel Corporation "C:\WINDOWS\system32\igfxtray.exe"
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run IntelTBRunOnce Microsoft Corporation wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
有効 HKLM:Run kssetup
有効 HKLM:Run Persistence Intel Corporation "C:\WINDOWS\system32\igfxpers.exe"
有効 HKLM:Run RtHDVBg Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
無効 HKLM:Run RtHDVCpl Realtek Semiconductor C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
有効 HKLM:Run SonicMasterTray Virage Logic Corporation / Sonic Focus C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
有効 HKLM:Run Wireless Console 3 ASUS C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe


IE-------------------------------------------------------------------------------
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension Send by Bluetooth to Atheros Commnucations C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
無効 Helper CIESpeechBHO Class Atheros Commnucations C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
有効 Helper Google Toolbar Helper Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
有効 Helper Google Toolbar Helper Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
無効 Helper Groove GFS Browser Helper Microsoft Corporation C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
無効 Helper Groove GFS Browser Helper Microsoft Corporation C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
無効 Helper i-フィルター 5.0 ブラウザヘルパー C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar64.dll
無効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
無効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
有効 Toolbar Google Toolbar Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
有効 Toolbar Google Toolbar Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll


google chrome-------------------------------------------------------------------------------
有効 App Gmail 8.1 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0
有効 App Google Search 0.0.0.30 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0
有効 App Google ドライブ 14.0 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.0_0
有効 App YouTube 4.2.7 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0
有効 Extension Google スプレッドシート 1.1 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0
有効 Extension Google スライド 0.9 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0
有効 Extension Google ドキュメント 0.9 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0


スケジュールされたタスク-------------------------------------------------------------------------------

有効 Task ACMON ASUS C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task ASUS Live Update ASUSTeK Computer Inc. C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
有効 Task ASUS P4G ASUS C:\Program Files\P4G\BatteryLife.exe
有効 Task ASUS Secure Delete C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
有効 Task ASUS SmartLogon Console Sensor ASUS C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
有効 Task ATKOSD2 ASUS C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
有効 Task Bidaily Synchronize Task[8da6] Super PC Tools Ltd c:\programdata\{5237d832-0a2d-6469-5237-7d8320a260c8}\hqghumeaylnlf.exe --startup=1 --single
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task SidebarExecute C:\Program Files\Windows Sidebar\sidebar.exe /addGadget
有効 Task StPrsSW C:\Users\【ユーザー名】\AppData\Roaming\StPrsSW\stprss.exe ,-clptsk
有効 Task Superclean Super PC Tools Ltd c:\programdata\{32e5e6e1-bf6a-1205-32e5-5e6e1bf69b86}\hqghumeaylnlf.exe --startup=1 --single
有効 Task USBChargerPlus ASUSTek Computer Inc. C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
有効 Task {FD25F9F0-DFC4-41AD-8F12-59A0BD6C9E0E} Microsoft Corporation C:\Windows\system32\pcalua.exe -a C:\Users\【ユーザー名】\Desktop\アクアリウムス1.80\Game.exe -d C:\Users\【ユーザー名】\Desktop\アクアリウムス1.80

  • ぐぬぬ
  • 2015/09/02 (Wed) 22:48:08
申し訳ありませんが
すみませんが、一度投稿したものを編集することはできますか?
できたら方法を教えていただきたいのですが・・・
どうやら、名前の一部が入ってしまっているようなので、そこを○○などに変更したいのですが・・・
  • ぐぬぬ
  • 2015/09/02 (Wed) 22:56:19
次回からは事前編集をお願いします
最初のHJTのログ、今回のスタートアップログに関してはこちらで一括置換しておきました。
次回からは投稿前に一括置換を行うか、根本的にPCに個人情報を登録しないか、
インターネットでつなぐ機器にむやみに本名等を登録するのは個人情報垂れ流しと同じですので、
これも勉強と思って今回はがんばってください。
編集を行う場合は編集ボタンをクリックして、パスワードの欄に登録した英数字を入力すればできます。
パスワードを未入力の場合は管理者権限がないと編集できません。

以下のソフトウェアをご用意ください。

「AdwCleaner」(通称:AC)
http://www.bleepingcomputer.com/download/adwcleaner/dl/125/
ファイル直リンクです。アクセスしてファイルを分かりやすい場所に保存しておいてください。
ソフトウェアを一度起動させることにより自動的にアップデートが始まります。
アップデートが完了しましたら今は何もせずに終了させてください。
本ソフトウェアの削除指示があった際は起動後に「アンインストール」ボタンを押せば自動で削除されます。

準備できたら作業を開始しましょう。
CCを起動させ、ツール→スタートアップの各項目を開き、
該当するものを無効→エントリの削除の順番でクリックしてください。

Windows
無効 HKLM:Run Adobe Reader Speed Launcher "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
有効 HKLM:Run kssetup

スケジュールされたタスク
有効 Task Bidaily Synchronize Task[8da6] Super PC Tools Ltd c:\programdata\{5237d832-0a2d-6469-5237-7d8320a260c8}\hqghumeaylnlf.exe --startup=1 --single
有効 Task StPrsSW C:\Users\【ユーザー名】\AppData\Roaming\StPrsSW\stprss.exe ,-clptsk
有効 Task Superclean Super PC Tools Ltd c:\programdata\{32e5e6e1-bf6a-1205-32e5-5e6e1bf69b86}\hqghumeaylnlf.exe --startup=1 --single

無効にできないもの、既に無効になっているものはそのままエントリの削除を、
エントリが存在しない場合は放置で先に進みましょう。
またGoogle Chrome等で削除ができない場合も放置で先に進みましょう。
CCでの作業が完了しましたら、PCをセーフモードで起動させてください。
ACを起動させ、Scanまたはスキャンをクリックします。
スキャンが終了しましたら、Cleaningまたは削除をクリックして掃除を行います。
掃除が完了すると再起動を求められますので、指示に従って通常モードで再起動を行ってください。
これでセーフモードから通常モードに移行します。
再起動前後いずれかにACのログが表示さますので、そちらを貼り付けてご連絡をお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/03 (Thu) 00:59:59
Re: DNSUnlockerの広告等々・・・
IVNOさん、返信ありがとうございます。
ユーザー名の件申し訳ありません。以後気を付けます。

CCの作業ですが、Windowsタブの
無効 HKLM:Run Adobe Reader Speed Launcher
はファイルが見つからないとのことで削除できませんでしたが、その他は削除できました。

以下ACログです。

# AdwCleaner v5.005 - ログファイルの作成日 03/09/2015 作成時間 20:18:58
# 更新日 31/08/2015 作成元 Xplode
# データベース : 2015-08-31.2 [ローカル]
# オペレーティングシステム : Windows 10 Home (x64)
# ユーザー名 : 【ユーザー名】 - 【ユーザー名】-PC
# 実行場所 : C:\Users\【ユーザー名】\Downloads\AdwCleaner.exe
# オプション : 削除
# サポート : http://toolslib.net/forum

***** [ サービス ] *****


***** [ フォルダ ] *****

[-] フォルダ 削除済み項目 : C:\Program Files (x86)\DNS Unlocker
[-] フォルダ 削除済み項目 : C:\ProgramData\AppVerifier
[-] フォルダ 削除済み項目 : C:\ProgramData\726a9a91e9097b86
[-] フォルダ 削除済み項目 : C:\ProgramData\{32e5e6e1-bf6a-1205-32e5-5e6e1bf69b86}
[-] フォルダ 削除済み項目 : C:\ProgramData\{5237d832-0a2d-6469-5237-7d8320a260c8}
[-] フォルダ 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\torch
[-] フォルダ 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\ShdUpdate
[-] フォルダ 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\RtbSync
[-] フォルダ 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ndkapieccepooddpgjdfiinfkiecmmhh
[!] フォルダ ノット 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ndkapieccepooddpgjdfiinfkiecmmhh
[-] フォルダ 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ndkapieccepooddpgjdfiinfkiecmmhh
[!] フォルダ ノット 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ndkapieccepooddpgjdfiinfkiecmmhh
[-] フォルダ 削除済み項目 : C:\Users\【ユーザー名】\AppData\Roaming\Updater
[-] フォルダ 削除済み項目 : C:\Users\【ユーザー名】\AppData\Roaming\EasyFileOpener

***** [ ファイル ] *****

[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_avg-anti-virus-free.softonic.jp_0.localstorage
[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_avg-anti-virus-free.softonic.jp_0.localstorage-journal
[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_torch-windows.softonic.jp_0.localstorage
[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_torch-windows.softonic.jp_0.localstorage-journal
[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.jp_0.localstorage
[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.jp_0.localstorage-journal

***** [ ショートカット ] *****


***** [ スケジュールタスク ] *****


***** [ レジストリ ] *****

[-] 値 削除済み項目 : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
[-] 値 削除済み項目 : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
[-] キー 削除済み項目 : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
[-] キー 削除済み項目 : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
[-] キー 削除済み項目 : HKCU\Software\5b6d68ce06ebe41
[-] キー 削除済み項目 : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
[-] キー 削除済み項目 : HKLM\SOFTWARE\5b6d68ce06ebe41
[-] キー 削除済み項目 : HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
[!] キー ノット 削除済み項目 : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
[-] キー 削除済み項目 : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] キー 削除済み項目 : HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
[!] キー ノット 削除済み項目 : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
[-] キー 削除済み項目 : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
[-] キー 削除済み項目 : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
[-] キー 削除済み項目 : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
[-] キー 削除済み項目 : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5F003B-C71B-72E3-42B4-DE51AB079EB2}
[-] キー 削除済み項目 : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1
[-] キー 削除済み項目 : [x64] HKLM\SOFTWARE\AppVerifierService

***** [ Webブラウザ ] *****


*************************

:: Winsock設定を初期化しました

########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [4675 バイト] ##########





  • ぐぬぬ
  • 2015/09/03 (Thu) 20:43:43
ACは削除しMBAMでスキャンを
ACの結果は良好です。
ACでもDNS Unlockerは表面上は対応してきていますね。
ACは不要となりますので、ACを起動させてアンインストールボタンを押して削除なされてください。

以下のソフトウェアをご用意ください。

Malwarebytes Anti-Malware(通称:MBAM)
旧バージョンダウンロード↓(ファイル直リンクです。表示して数秒後にダウンロード開始の表示が出ます)
http://www.oldapps.com/malwarebytes.php?old_malwarebytes=12090?download
Google Chrome以外のブラウザでダウンロードしてください。
最新バージョンには動作しなくなるなどの不具合があるため、ここでは旧バージョンを利用します。
インストールの最後に出てくるMalwarebytes Anti-Malware Pro版の無料試用を開始する。のチェックを外します。
このソフトウェアは日本語対応ではありますが、初回起動時は文字化けしておりますので、以下の手順で日本語化を行ってください。
MBAMを起動させてください。
MBAMを起動時に自動アップデートが始まります。
最新バージョンをダウンロードしたと表示されたら、必ずキャンセルを押してください。
次にウイルス定義ファイルのアップデートが始まりますので、アップデート終了までお待ちください。
ウイルス定義ファイルのバージョンアップが完了すると、再度最新バージョンをダウンロードしたと出ますので、
再びキャンセルを押してアップデートを中止してください。
MBAMが起動したら設定タブを開き、Languageの項目の部分をJapaneseに再度変更することで日本語化が可能です。
この段階ではスキャンは行いませんので、設定が完了したらMBAMを終了させておいてください。
最新バージョンと旧バージョンは操作方法が大幅に異なりますので、
万一バージョン2.0以降を導入されてしまった場合はご連絡ください。
片付け時はセーフモードでGUを利用してアンインストールしてください。

ここで使うのはFree(無償版)です。

準備が完了しましたら作業を開始いたします。
PCをセーフモードで起動してください。
MBAMを起動させます。
フルスキャンを選択し、スキャン開始をクリックします。
スキャン終了まで30分~1時間半程度お待ちください。
スキャンが完了したら、詳細を表示をクリックします。
検出されたものの一覧が出ますので、検出されたものすべてを駆除するため、
検出されたものの左側にあるチェックボックスすべてにチェックを入れます。
すべての箇所にチェックを入れたら選択されたアイテムを隔離ボタンを押します。
処置の設定が完了するとPCの再起動を促されますので、指示に従って通常モードで再起動してください。
再起動前後にログが出ますので、取得されたログを貼り付け、ご報告をお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/03 (Thu) 20:50:34
Re: DNSUnlockerの広告等々・・・
スキャンと隔離が終了しました。
ログは再起動前に出て来たのですがそちらでよろしいでしょうか?
以下ログです。


Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

定義バージョン: v2015.09.03.04

Windows 8 x64 NTFS (セーフモード)
Internet Explorer 11.0.10240.16431
【ユーザー名】 :: 【ユーザー名】-PC [管理者]

2015/09/03 21:55:49
mbam-log-2015-09-03 (21-55-49).txt

スキャンタイプ: フルスキャン (C:\|D:\|)
有効なスキャン領域: メモリ | スタートアップ | レジストリ | ファイルシステム | ヒューリスティック/追加アイテムのスキャン  | ヒューリスティック/Shuriken エンジンを使用してスキャン  | 不審なプログラム (PUP) | 不審な変更 (PUM)
無効なスキャン領域: ピア・ツー・ピアプログラム(P2P)
スキャンしたアイテム数: 571201
経過時間: 56 分, 34 秒

メモリプロセスの検出: 0
(悪意のあるアイテムは検出されていません。)

メモリモジュールの検出: 0
(悪意のあるアイテムは検出されていません。)

レジストリキーの検出: 1
HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE (PUM.Security.Hijack.DisableChromeUpdates) -> 正常に隔離され削除されました。

レジストリ値の検出: 1
HKLM\SOFTWARE\Policies\Google\Update|DisableAutoUpdateChecksCheckboxValue (PUM.Security.Hijack.DisableChromeUpdates) -> データ: 1 -> 正常に隔離され削除されました。

レジストリデータ項目の検出: 2
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{857478e4-9b24-42e0-a39e-a800a9c0b3d5}|NameServer (Trojan.DNSChanger) -> 悪: (82.163.143.169,82.163.142.171) 良: () -> 正常に隔離され修復されました。
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{cfc30fb7-e730-4f6c-ac70-34c05625133f}|NameServer (Trojan.DNSChanger) -> 悪: (82.163.143.172,82.163.142.174) 良: () -> 正常に隔離され修復されました。

フォルダの検出: 0
(悪意のあるアイテムは検出されていません。)

ファイルの検出: 0
(悪意のあるアイテムは検出されていません。)

(終)
  • ぐぬぬ
  • 2015/09/03 (Thu) 23:06:53
なかなか面白い検出結果です
MBAMの処置は正常に完了しましたが、ちょっとここしばらく見なかったものが出ていましたね。
MBAMは不要となりますので、導入時の指示に従って削除なされてください。
次はいよいよ手動での叩き出しです。

以下のソフトウェアをご準備ください。

OldTimer Listit(通称:OTL)
http://oldtimer.geekstogo.com/OTL.exe
直リンクです。デスクトップ等、分かりやすい場所に保存してください。
削除する際は起動後に「Cleanup」ボタンを押すことにより、自動的に削除されます。

OTLを起動させる前にブラウザを含め、可能な限りのソフトウェアを終了させてください。
ソフトウェアの終了が完了しましたら、OTLを起動させてください。
表示画面上部中央にあるScan All Usersにチェックを入れてください。
設定が完了しましたら、Custom Scan/Fixesの項目内に以下をコピペしてください。

------コピペこの下より------
SHOWHIDDEN
%windir%\tasks\*.job
DRIVES
BASESERVICES
%SYSTEMDRIVE%\*.exe
ACTIVEX
CREATERESTOREPOINT
------コピペこの上まで------

コピペが完了しましたら、Run Scanをクリックしてスキャンを行ってください。
スキャン完了まで数分程度かかりますので、今しばらくお待ちください。
スキャンが完了しましたら、OTLを保存した場所と同じところに、
OTL.txtとExtras.txtが出力されますので、そちらを貼り付けてご連絡ください。
なお、OTLはその特性上、非常に長文となります。
こちらの掲示板の文字数上限がひらがな換算で約3万文字、英数字換算で約6万文字です。
確実に文字数オーバーとなりますので、余裕を見て5万5千文字程度になるように、
以下のURLの文字数カウンター等で確認しつつ、ログを分割されてご連絡ください。
http://www2u.biglobe.ne.jp/~yuichi/rest/strcount.html
  • IVNO
  • MAIL
  • 2015/09/04 (Fri) 01:30:30
申し訳ありません
申し訳ありません!またやってしまいました!
修正済みのものを投稿しなおしますのでOTL 1/4~OTL 3/4を削除してください。
同じミスをしてしまい申し訳ありません。

以下修正済みログです
OTL 1/4

OTL logfile created on: 2015/09/04 20:08:22 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\【ユーザー名】\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.10240.16384)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.91 Gb Total Physical Memory | 5.97 Gb Available Physical Memory | 75.41% Memory free
15.91 Gb Paging File | 14.01 Gb Available in Paging File | 88.07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.45 Gb Total Space | 211.00 Gb Free Space | 75.50% Space Free | Partition Type: NTFS
Drive D: | 394.18 Gb Total Space | 393.85 Gb Free Space | 99.92% Space Free | Partition Type: NTFS

Computer Name: 【ユーザー名】-PC | User Name: 【ユーザー名】 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - File not found --
PRC - [2015/09/04 20:06:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\【ユーザー名】\Downloads\OTL.exe
PRC - [2015/08/28 20:10:12 | 000,404,064 | ---- | M] (Microsoft Corporation) -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe
PRC - [2015/07/07 20:12:28 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/08/26 19:27:44 | 003,233,806 | ---- | M] () -- C:\Program Files (x86)\Tor\tor.exe
PRC - [2012/04/17 11:05:18 | 003,058,304 | ---- | M] (ASUS) -- C:\Windows\AsScrPro.exe
PRC - [2011/08/31 15:33:32 | 001,545,856 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
PRC - [2011/08/24 14:53:24 | 000,100,992 | ---- | M] (ASUS) -- C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe
PRC - [2011/08/24 14:53:22 | 000,092,800 | ---- | M] (ASUS) -- C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
PRC - [2011/07/21 15:49:10 | 005,716,608 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
PRC - [2011/07/18 15:11:42 | 000,166,528 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
PRC - [2011/06/17 17:19:54 | 000,502,704 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
PRC - [2011/06/10 10:49:10 | 002,255,360 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
PRC - [2011/05/30 13:48:18 | 000,082,944 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
PRC - [2011/05/30 13:48:16 | 000,155,648 | ---- | M] (ASUSTeK) -- C:\Windows\SysWOW64\ACEngSvr.exe
PRC - [2011/02/22 13:13:50 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2011/02/22 13:13:46 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2011/01/06 20:08:38 | 000,138,400 | ---- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2010/11/15 10:42:12 | 000,305,792 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
PRC - [2010/10/07 14:05:14 | 000,170,624 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
PRC - [2010/08/20 09:57:06 | 000,107,816 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
PRC - [2010/07/09 22:45:00 | 000,984,400 | ---- | M] (Virage Logic Corporation / Sonic Focus) -- C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
PRC - [2009/12/15 10:39:38 | 000,096,896 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
PRC - [2009/06/19 10:29:42 | 000,105,016 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
PRC - [2009/06/19 10:29:26 | 002,488,888 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
PRC - [2009/06/15 17:30:42 | 000,084,536 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
PRC - [2008/12/22 17:15:34 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
PRC - [2008/08/13 21:00:08 | 000,113,208 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2011/08/31 15:33:32 | 000,208,384 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
MOD - [2011/06/10 10:49:10 | 001,163,264 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
MOD - [2011/05/30 13:48:14 | 000,009,216 | ---- | M] () -- C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
MOD - [2010/08/20 09:57:06 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2010/08/20 09:57:00 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2015/08/28 18:17:58 | 000,280,064 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:57 | 001,031,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorDataService.exe -- (SensorDataService)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 001,420,288 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\UserDataService.dll -- (UserDataSvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 001,203,200 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Unistore.dll -- (UnistoreSvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 001,169,408 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dosvc.dll -- (DoSvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,343,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\usocore.dll -- (UsoSvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,229,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorService.dll -- (SensorService)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,808,856 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,658,568 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ClipSVC.dll -- (ClipSVC)
SRV:[b]64bit:[/b] - [2015/08/28 18:12:49 | 000,084,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:12:39 | 000,026,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mqsvc.exe -- (MSMQ)
SRV:[b]64bit:[/b] - [2015/08/18 15:58:25 | 000,187,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NetSetupSvc.dll -- (NetSetupSvc)
SRV:[b]64bit:[/b] - [2015/08/18 15:55:01 | 002,178,560 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2015/08/18 15:54:03 | 000,322,048 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2015/08/13 13:22:26 | 002,093,056 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2015/08/11 18:50:47 | 001,643,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:[b]64bit:[/b] - [2015/08/11 18:21:13 | 000,148,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tetheringservice.dll -- (icssvc)
SRV:[b]64bit:[/b] - [2015/08/11 18:07:52 | 000,593,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2015/08/11 18:05:10 | 000,996,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\RDXService.dll -- (RetailDemo)
SRV:[b]64bit:[/b] - [2015/08/03 10:24:19 | 000,503,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\tileobjserver.dll -- (tiledatamodelsvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:10 | 000,621,056 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:10 | 000,504,320 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WalletService.dll -- (WalletService)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:10 | 000,074,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:41 | 000,167,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:38 | 001,844,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:36 | 000,115,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:20 | 000,749,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:16 | 000,075,264 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,526,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,337,408 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,289,280 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\PimIndexMaintenance.dll -- (PimIndexMaintenanceSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wpnservice.dll -- (WpnService)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,033,280 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DevQueryBroker.dll -- (DevQueryBroker)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,027,136 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lfsvc.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 002,674,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\Windows.StateRepository.dll -- (StateRepository)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 001,149,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblGameSave.dll -- (XblGameSave)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 001,019,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XboxNetApiSvc.dll -- (XboxNetApiSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,512,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ngcsvc.dll -- (NgcSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,268,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NgcCtnrSvc.dll -- (NgcCtnrSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,062,464 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\moshost.dll -- (MapsBroker)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,023,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AJRouter.dll -- (AJRouter)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,021,504 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\LicenseManagerSvc.dll -- (LicenseManager)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:06 | 000,134,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\cdpsvc.dll -- (CDPSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:06 | 000,087,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\embeddedmodesvc.dll -- (embeddedmode)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:03 | 003,467,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,918,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblAuthManager.dll -- (XblAuthManager)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,836,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,055,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,096,256 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,717,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\usermgr.dll -- (UserManager)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,181,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,296,960 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\APHostService.dll -- (OneSyncSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,196,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dcpsvc.dll -- (DcpSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,027,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe -- (diagnosticshub.standardcollector.service)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,143,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dssvc.dll -- (DsSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,039,856 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\svchost.exe -- (UserDataSvc_Session1)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,039,856 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\svchost.exe -- (UnistoreSvc_Session1)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,039,856 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\svchost.exe -- (PimIndexMaintenanceSvc_Session1)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,039,856 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\svchost.exe -- (OneSyncSvc_Session1)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:57 | 000,405,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:57 | 000,237,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:56 | 000,019,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:55 | 000,118,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:55 | 000,013,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:54 | 000,275,456 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll -- (EntAppSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,267,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,063,488 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dmwappushsvc.dll -- (dmwappushservice)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:51 | 000,583,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SmsRouterSvc.dll -- (SmsRouter)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,550,400 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,379,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,362,928 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,167,936 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvmsession)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,024,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:37 | 003,337,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,326,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv)
SRV:[b]64bit:[/b] - [2015/06/03 03:16:46 | 000,249,032 | ---- | M] (Synaptics Incorporated) [Auto | Running] -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe -- (SynTPEnhService)
SRV:[b]64bit:[/b] - [2011/03/03 16:57:58 | 000,379,520 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent)
SRV:[b]64bit:[/b] - [2010/11/29 15:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:[b]64bit:[/b] - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2015/08/28 18:17:54 | 000,925,696 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Unistore.dll -- (UnistoreSvc)
SRV - [2015/08/28 18:17:53 | 000,510,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV - [2015/08/28 18:12:57 | 000,504,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2015/08/28 18:12:57 | 000,504,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2015/08/28 18:12:46 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV - [2015/08/28 18:12:43 | 000,056,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2015/08/12 02:07:16 | 000,269,000 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015/07/10 20:00:30 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\lfsvc.dll -- (lfsvc)
SRV - [2015/07/10 20:00:29 | 002,049,024 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\Windows.StateRepository.dll -- (StateRepository)
SRV - [2015/07/10 20:00:24 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2015/07/10 20:00:23 | 000,193,024 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV - [2015/07/10 19:59:37 | 003,337,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2015/07/07 20:12:28 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2015/06/01 21:00:40 | 000,290,224 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2013/08/26 19:27:44 | 003,233,806 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Tor\tor.exe -- (tor)
SRV - [2011/08/24 14:53:22 | 000,092,800 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe -- (ASUS InstantOn)
SRV - [2011/02/22 13:13:50 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/02/22 13:13:46 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011/01/06 20:08:38 | 000,138,400 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2009/12/15 10:39:38 | 000,096,896 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
SRV - [2009/06/15 17:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2015/08/28 20:08:32 | 000,410,880 | ---- | M] (Realsil Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUer.sys -- (RTSUER)
DRV:[b]64bit:[/b] - [2015/08/28 20:06:45 | 000,599,240 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,934,752 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refsv1.sys -- (ReFSv1)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,061,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,067,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,046,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmUcsi.sys -- (UcmUcsi)
DRV:[b]64bit:[/b] - [2015/08/28 18:12:56 | 000,175,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mqac.sys -- (MQAC)
DRV:[b]64bit:[/b] - [2015/08/18 16:55:45 | 000,373,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2015/08/11 19:02:56 | 000,080,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2015/08/06 12:17:40 | 000,200,528 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2015/08/06 11:22:03 | 000,685,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdiWiFi.sys -- (wdiwifi)
DRV:[b]64bit:[/b] - [2015/08/03 11:18:37 | 000,046,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2015/08/03 11:17:53 | 000,052,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2015/08/03 11:17:45 | 000,516,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2015/07/11 01:34:25 | 000,038,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2015/07/11 01:34:15 | 000,029,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2015/07/10 20:01:20 | 000,029,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:14 | 000,380,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:14 | 000,215,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,106,520 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRT.sys -- (WindowsTrustedRT)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,061,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmCx.sys -- (UcmCx0101)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,031,072 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,200,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,153,440 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,061,952 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\storqosflt.sys -- (storqosflt)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,041,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,026,624 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ioqos.sys -- (IoQos)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:04 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mmcss.sys -- (MMCSS)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,245,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufx01000.sys -- (Ufx01000)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,159,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,077,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,074,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urscx01000.sys -- (UrsCx01000)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,039,264 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cnghwassist.sys -- (cnghwassist)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,155,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,088,928 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:56 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\gpuenergydrv.sys -- (GpuEnergyDrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,129,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,124,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:52 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,119,648 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,082,432 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,291,680 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,209,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Ucx01000.sys -- (Ucx01000)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,127,840 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,098,144 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,083,968 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\filecrypt.sys -- (FileCrypt)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,044,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,044,032 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Udecx.sys -- (UdeCx)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,031,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhf.sys -- (vhf)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,028,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urschipidea.sys -- (UrsChipidea)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urssynopsys.sys -- (UrsSynopsys)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,017,944 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRTProxy.sys -- (WindowsTrustedRTProxy)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,705,376 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mlx4_bus.sys -- (mlx4_bus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,587,264 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rt640x64.sys -- (rt640x64)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,474,464 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,424,800 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ibbus.sys -- (ibbus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,133,984 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,127,840 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufxsynopsys.sys -- (ufxsynopsys)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,094,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UfxChipidea.sys -- (UfxChipidea)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,077,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,076,128 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndfltr.sys -- (ndfltr)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,059,232 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winverbs.sys -- (WinVerbs)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,058,720 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas3i.sys -- (percsas3i)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,058,208 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas2i.sys -- (percsas2i)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,055,296 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,040,288 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storufs.sys -- (storufs)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,028,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,026,976 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winmad.sys -- (WinMad)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,017,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys -- (swenum)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 003,436,896 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 001,135,456 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,673,120 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,222,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xboxgip.sys -- (xboxgip)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,207,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,116,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\capimg.sys -- (CapImg)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,107,360 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,104,800 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2i.sys -- (LSI_SAS2i)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,099,168 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3i.sys -- (LSI_SAS3i)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,083,296 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,050,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidinterrupt.sys -- (hidinterrupt)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\buttonconverter.sys -- (buttonconverter)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,026,976 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xinputhid.sys -- (xinputhid)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\genericusbfn.sys -- (genericusbfn)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,276,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,122,608 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,116,576 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,094,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,092,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,064,000 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,043,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,042,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys -- (CompositeBus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,038,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fcvsc.sys -- (fcvsc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2015/06/03 03:16:46 | 000,613,576 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2015/06/03 03:16:44 | 000,042,696 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV:[b]64bit:[/b] - [2015/06/01 21:00:18 | 005,384,176 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2013/08/14 03:42:44 | 003,837,440 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athwbx.sys -- (athr)
DRV:[b]64bit:[/b] - [2011/09/22 21:01:54 | 000,311,144 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\RsFx0105.sys -- (RsFx0105)
DRV:[b]64bit:[/b] - [2011/05/13 15:37:54 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:[b]64bit:[/b] - [2011/02/25 17:42:18 | 000,016,768 | ---- | M] (ASUSTek Computer Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AiCharger.sys -- (AiCharger)
DRV:[b]64bit:[/b] - [2011/01/06 20:07:26 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:[b]64bit:[/b] - [2010/11/29 15:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:[b]64bit:[/b] - [2010/11/06 00:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2010/10/15 02:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2010/04/28 09:59:16 | 000,027,264 | ---- | M] (ASUS Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\assd.sys -- (assd)
DRV:[b]64bit:[/b] - [2009/07/20 18:29:40 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
DRV:[b]64bit:[/b] - [2008/05/23 17:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2015/07/10 19:59:39 | 000,017,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys -- (swenum)
DRV - [2015/07/10 19:59:36 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys -- (CompositeBus)
DRV - [2011/09/07 09:55:04 | 000,017,536 | ---- | M] (ASUS) [Kernel | System | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys -- (ATKWMIACPIIO)
DRV - [2009/07/02 17:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7




IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm

IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGNI_jaJP491
IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.60.2: C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.60.2: C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@TrendMicro.com/FFExtension: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\【ユーザー名】\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)


[2013/03/26 17:37:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

[color=#E56717]========== Chrome ==========[/color]

CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.0_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
  • ぐぬぬ
  • 2015/09/04 (Fri) 21:11:21
Re: DNSUnlockerの広告等々・・・
OTL 2/4

O1 HOSTS File: ([2009/06/11 06:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (i-フィルター 5.0 ブラウザヘルパー) - {0FAF6F52-1AD4-4282-9EA1-3EC884DA7AA3} - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar64.dll File not found
O2:[b]64bit:[/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:[b]64bit:[/b] - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:[b]64bit:[/b] - HKLM..\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" File not found
O4:[b]64bit:[/b] - HKLM..\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe File not found
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\WINDOWS\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ASUSPRP] C:\Program Files (x86)\ASUS\APRP\APRP.EXE (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe (ecareme)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (Virage Logic Corporation / Sonic Focus)
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUS)
O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3922431837-200563891-1274897566-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-3922431837-200563891-1274897566-1000..\Run: [OneDrive] C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab (Microsoft Office Template and Media Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{857478e4-9b24-42e0-a39e-a800a9c0b3d5}: DhcpNameServer = 172.16.1.21 172.16.1.42
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{cfc30fb7-e730-4f6c-ac70-34c05625133f}: DhcpNameServer = 192.168.0.1
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30:[b]64bit:[/b] - LSA: Security Packages - (livessp) - File not found
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {C49181C5-51A7-39B8-A058-B35C7BAD6E1F} - .NET Framework
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\inf\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D3D70DDE-B3B4-33DE-A8CD-808A85D68682} - .NET Framework
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015/09/03 21:38:12 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Malwarebytes
[2015/09/03 21:37:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015/09/02 22:45:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2015/09/02 21:55:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2015/09/02 21:37:41 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Geek Uninstaller
[2015/09/02 21:34:12 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\geek
[2015/09/01 23:59:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2015/09/01 23:59:16 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2015/08/31 01:24:09 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\契約の対価
[2015/08/29 19:57:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AV
[2015/08/29 18:35:17 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\NetworkTiles
[2015/08/29 15:48:40 | 021,875,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2015/08/29 15:48:37 | 018,806,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2015/08/29 15:48:34 | 002,225,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetworkMobileSettings.dll
[2015/08/29 15:48:34 | 001,396,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicenseManager.dll
[2015/08/29 15:48:33 | 008,019,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2015/08/29 15:48:32 | 001,888,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2015/08/29 15:48:32 | 000,963,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LicenseManager.dll
[2015/08/29 15:48:32 | 000,859,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\modernexecserver.dll
[2015/08/29 15:48:31 | 001,593,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2015/08/29 15:48:31 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetSetupShim.dll
[2015/08/29 15:48:30 | 000,609,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2015/08/29 15:48:30 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\NetSetupShim.dll
[2015/08/29 15:48:30 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetSetupSvc.dll
[2015/08/29 15:48:29 | 001,061,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\reseteng.dll
[2015/08/29 15:48:29 | 000,373,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2015/08/29 15:48:29 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BthRadioMedia.dll
[2015/08/29 15:48:29 | 000,077,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2015/08/29 15:48:28 | 001,294,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcnwiz.dll
[2015/08/29 15:48:28 | 001,234,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aitstatic.exe
[2015/08/29 15:48:28 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WlanMediaManager.dll
[2015/08/29 15:48:28 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InstallAgent.exe
[2015/08/29 15:48:28 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnNetsh.dll
[2015/08/29 15:48:28 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wfdprov.dll
[2015/08/29 15:48:27 | 001,226,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wcnwiz.dll
[2015/08/29 15:48:27 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EnterpriseModernAppMgmtCSP.dll
[2015/08/29 15:48:27 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnApi.dll
[2015/08/29 15:48:27 | 000,100,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WcnApi.dll
[2015/08/29 15:48:27 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wfdprov.dll
[2015/08/29 15:48:26 | 002,178,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2015/08/29 15:48:26 | 001,795,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.dll
[2015/08/29 15:48:26 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PackageStateRoaming.dll
[2015/08/29 15:48:26 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafWCN.dll
[2015/08/29 15:48:26 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fdWCN.dll
[2015/08/29 15:48:25 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vaultsvc.dll
[2015/08/29 15:48:25 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PackageStateRoaming.dll
[2015/08/29 00:10:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SleepStudy
[2015/08/28 22:32:39 | 008,613,200 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\SysNative\Windows.Media.Protection.PlayReady.dll
[2015/08/28 22:32:39 | 006,878,256 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
[2015/08/28 22:32:29 | 016,706,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2015/08/28 22:32:21 | 013,024,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2015/08/28 22:32:21 | 003,780,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_nt.dll
[2015/08/28 22:32:17 | 002,415,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2015/08/28 22:32:14 | 003,527,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tquery.dll
[2015/08/28 22:32:13 | 002,558,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssrch.dll
[2015/08/28 22:32:12 | 004,532,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2015/08/28 22:32:12 | 001,212,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RemoteNaturalLanguage.dll
[2015/08/28 22:32:11 | 002,462,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2015/08/28 22:32:11 | 002,416,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2015/08/28 22:32:11 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Speech.dll
[2015/08/28 22:32:10 | 007,523,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2015/08/28 22:32:10 | 001,643,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diagtrack.dll
[2015/08/28 22:32:10 | 001,601,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Speech.dll
[2015/08/28 22:32:10 | 000,898,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\RemoteNaturalLanguage.dll
[2015/08/28 22:32:09 | 004,048,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2015/08/28 22:32:09 | 002,093,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidsvc.dll
[2015/08/28 22:32:09 | 000,595,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LogonController.dll
[2015/08/28 22:32:08 | 002,151,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2015/08/28 22:32:08 | 000,583,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mf.dll
[2015/08/28 22:32:07 | 001,964,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssrch.dll
[2015/08/28 22:32:06 | 000,778,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.dll
[2015/08/28 22:32:06 | 000,644,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsvr.dll
[2015/08/28 22:32:06 | 000,494,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LogonController.dll
[2015/08/28 22:32:05 | 002,748,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tquery.dll
[2015/08/28 22:32:05 | 001,916,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2015/08/28 22:32:05 | 000,996,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RDXService.dll
[2015/08/28 22:32:04 | 003,588,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2015/08/28 22:32:04 | 001,383,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kbase.sys
[2015/08/28 22:32:04 | 000,783,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsvr.dll
[2015/08/28 22:32:04 | 000,586,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
[2015/08/28 22:32:03 | 000,292,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockAppHost.exe
[2015/08/28 22:32:03 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.LockScreen.dll
[2015/08/28 22:32:03 | 000,195,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.LockScreen.dll
[2015/08/28 22:32:02 | 005,454,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2015/08/28 22:32:02 | 000,801,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WWAHost.exe
[2015/08/28 22:32:02 | 000,505,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms2.sys
[2015/08/28 22:32:02 | 000,365,056 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysNative\atmfd.dll
[2015/08/28 22:32:02 | 000,310,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActionCenter.dll
[2015/08/28 22:32:01 | 001,334,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIAutomationCore.dll
[2015/08/28 22:32:01 | 000,700,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WWAHost.exe
[2015/08/28 22:32:01 | 000,303,104 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\atmfd.dll
[2015/08/28 22:32:01 | 000,243,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LockAppHost.exe
[2015/08/28 22:32:01 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SubscriptionMgr.dll
[2015/08/28 22:32:01 | 000,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetworkStatus.dll
[2015/08/28 22:32:00 | 000,918,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2015/08/28 22:32:00 | 000,893,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApiPublic.dll
[2015/08/28 22:32:00 | 000,608,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fontdrvhost.exe
[2015/08/28 22:31:59 | 001,274,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wifinetworkmanager.dll
[2015/08/28 22:31:59 | 000,685,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdiWiFi.sys
[2015/08/28 22:31:59 | 000,554,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\directmanipulation.dll
[2015/08/28 22:31:59 | 000,261,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ActionCenter.dll
[2015/08/28 22:31:59 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinBioDataModel.dll
[2015/08/28 22:31:58 | 001,112,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIAutomationCore.dll
[2015/08/28 22:31:58 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctfuimanager.dll
[2015/08/28 22:31:58 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msctfuimanager.dll
[2015/08/28 22:31:58 | 000,454,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\directmanipulation.dll
[2015/08/28 22:31:58 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationObjFactory.dll
[2015/08/28 22:31:58 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\NotificationObjFactory.dll
[2015/08/28 22:31:57 | 000,593,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmsvc.dll
[2015/08/28 22:31:57 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.Desktop.dll
[2015/08/28 22:31:57 | 000,563,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApi.dll
[2015/08/28 22:31:57 | 000,539,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fontdrvhost.exe
[2015/08/28 22:31:57 | 000,516,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS
[2015/08/28 22:31:56 | 001,087,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2015/08/28 22:31:56 | 000,993,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgent.dll
[2015/08/28 22:31:56 | 000,317,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\configmanager2.dll
[2015/08/28 22:31:56 | 000,200,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wof.sys
[2015/08/28 22:31:56 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationPermissions.dll
[2015/08/28 22:31:56 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VPNv2CSP.dll
[2015/08/28 22:31:55 | 001,822,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2015/08/28 22:31:55 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Notifications.dll
[2015/08/28 22:31:55 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserMgrProxy.dll
[2015/08/28 22:31:55 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
[2015/08/28 22:31:55 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cloudAP.dll
[2015/08/28 22:31:54 | 000,671,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApiPublic.dll
[2015/08/28 22:31:54 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\coredpus.dll
[2015/08/28 22:31:53 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApi.dll
[2015/08/28 22:31:53 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tetheringservice.dll
[2015/08/28 22:31:53 | 000,080,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\stornvme.sys
[2015/08/28 22:31:53 | 000,052,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wpcfltr.sys
[2015/08/28 22:31:52 | 000,642,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdbui.dll
[2015/08/28 22:31:52 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationGeofences.dll
[2015/08/28 22:31:52 | 000,336,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchProtocolHost.exe
[2015/08/28 22:31:52 | 000,159,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserMgrProxy.dll
[2015/08/28 22:31:52 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeParserTask.exe
[2015/08/28 22:31:51 | 000,845,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgent.dll
[2015/08/28 22:31:51 | 000,594,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Shell.Broker.dll
[2015/08/28 22:31:51 | 000,483,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OneDriveSettingSyncProvider.dll
[2015/08/28 22:31:51 | 000,311,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2015/08/28 22:31:51 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\syncutil.dll
[2015/08/28 22:31:51 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationFramework.dll
[2015/08/28 22:31:51 | 000,046,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\msgpiowin32.sys
[2015/08/28 22:31:49 | 000,442,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\storport.sys
[2015/08/28 22:31:49 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2015/08/28 22:31:49 | 000,243,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfps.dll
[2015/08/28 22:31:49 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuautoappupdate.dll
[2015/08/28 22:31:48 | 000,393,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms1.sys
[2015/08/28 22:31:48 | 000,372,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\OneDriveSettingSyncProvider.dll
[2015/08/28 22:31:48 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tetheringclient.dll
[2015/08/28 22:31:47 | 000,621,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enterprisecsps.dll
[2015/08/28 22:31:47 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tetheringclient.dll
[2015/08/28 22:31:45 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GamePanel.exe
[2015/08/28 22:31:45 | 000,384,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockAppBroker.dll
[2015/08/28 22:31:45 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Core.TextInput.dll
[2015/08/28 22:31:45 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssprxy.dll
[2015/08/28 22:31:45 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationFrameworkInternalPS.dll
[2015/08/28 22:31:44 | 001,290,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Shell.dll
[2015/08/28 22:31:44 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GamePanel.exe
[2015/08/28 22:31:44 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/08/28 22:31:44 | 000,311,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LockAppBroker.dll
[2015/08/28 22:31:44 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/08/28 22:31:44 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SharedStartModelShim.dll
[2015/08/28 22:31:44 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReInfo.dll
[2015/08/28 22:31:43 | 000,911,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SharedStartModel.dll
[2015/08/28 22:31:43 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tileobjserver.dll
[2015/08/28 22:31:43 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VEEventDispatcher.dll
[2015/08/28 22:31:42 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VEEventDispatcher.dll
[2015/08/28 22:31:42 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_UserAccount.dll
[2015/08/28 22:31:42 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VEDataLayerHelpers.dll
[2015/08/28 22:31:42 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VEDataLayerHelpers.dll
[2015/08/28 20:08:40 | 000,000,000 | R--D | C] -- C:\Users\【ユーザー名】\OneDrive
[2015/08/28 20:08:32 | 009,898,752 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SysWow64\RsCRIcon.dll
[2015/08/28 20:06:58 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\MicrosoftEdge
[2015/08/28 20:06:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Atheros
[2015/08/28 20:06:45 | 000,599,240 | ---- | C] (Qualcomm Atheros) -- C:\WINDOWS\SysNative\drivers\btfilter.sys
[2015/08/28 20:06:45 | 000,011,264 | ---- | C] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll.muien-US
[2015/08/28 20:06:44 | 000,182,784 | ---- | C] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll
[2015/08/28 20:06:44 | 000,181,760 | ---- | C] (Qualcomm Atheros Communications Inc.) -- C:\WINDOWS\SysNative\btcoinst.dll
[2015/08/28 20:06:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft OneDrive
[2015/08/28 20:05:53 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Comms
[2015/08/28 20:05:18 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Publishers
[2015/08/28 20:03:00 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\TileDataLayer
[2015/08/28 19:01:57 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favorites
[2015/08/28 18:55:03 | 002,718,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintConfig.dll
[2015/08/28 18:41:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SpeechEngines
[2015/08/28 18:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2015/08/28 18:34:27 | 000,000,000 | --SD | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft
[2015/08/28 18:34:27 | 000,000,000 | R-SD | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
[2015/08/28 18:34:27 | 000,000,000 | R--D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2015/08/28 18:34:27 | 000,000,000 | R--D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2015/08/28 18:34:27 | 000,000,000 | R--D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\スタート メニュー
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\AppData\Local\Temporary Internet Files
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Templates
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\SendTo
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Recent
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\PrintHood
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\NetHood
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Documents\My Videos
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Documents\My Pictures
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Documents\My Music
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\My Documents
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Local Settings
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\AppData\Local\History
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Cookies
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Application Data
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\AppData\Local\Application Data
[2015/08/28 18:34:27 | 000,000,000 | -H-D | C] -- C:\Users\【ユーザー名】\AppData
[2015/08/28 18:34:27 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Temp
[2015/08/28 18:34:27 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft
[2015/08/28 18:34:27 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2015/08/28 18:31:03 | 000,000,000 | ---D | C] -- C:\ProgramData\SonicFocus
[2015/08/28 18:30:51 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2015/08/28 18:30:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RTCOM
[2015/08/28 18:30:44 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2015/08/28 18:30:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sda
[2015/08/28 18:26:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2015/08/28 18:24:34 | 000,000,000 | -HSD | C] -- C:\Recovery
[2015/08/28 18:18:06 | 001,561,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll
[2015/08/28 18:18:06 | 001,356,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll
[2015/08/28 18:18:06 | 000,569,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MCRecvSrc.dll
[2015/08/28 18:18:06 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToManager.dll
[2015/08/28 18:18:06 | 000,480,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MCRecvSrc.dll
[2015/08/28 18:18:06 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcastdvr.exe
[2015/08/28 18:17:58 | 014,241,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmp.dll
[2015/08/28 18:17:58 | 012,589,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmp.dll
[2015/08/28 18:17:58 | 004,791,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2015/08/28 18:17:58 | 003,248,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2015/08/28 18:17:58 | 002,646,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2015/08/28 18:17:58 | 001,562,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll
[2015/08/28 18:17:58 | 001,411,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Editing.dll
[2015/08/28 18:17:58 | 001,043,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Editing.dll
[2015/08/28 18:17:58 | 001,043,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2015/08/28 18:17:58 | 001,025,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsrcsnk.dll
[2015/08/28 18:17:58 | 000,980,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SecConfig.efi
[2015/08/28 18:17:58 | 000,896,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsrcsnk.dll
[2015/08/28 18:17:58 | 000,877,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2015/08/28 18:17:58 | 000,846,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpncore.dll
[2015/08/28 18:17:58 | 000,816,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmpeg2srcsnk.dll
[2015/08/28 18:17:58 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpccpl.dll
[2015/08/28 18:17:58 | 000,713,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
[2015/08/28 18:17:58 | 000,670,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieproxy.dll
[2015/08/28 18:17:58 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpnapps.dll
[2015/08/28 18:17:58 | 000,584,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Sensors.dll
[2015/08/28 18:17:58 | 000,527,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2015/08/28 18:17:58 | 000,521,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PsmServiceExtHost.dll
[2015/08/28 18:17:58 | 000,501,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2015/08/28 18:17:58 | 000,487,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmkvsrcsnk.dll
[2015/08/28 18:17:58 | 000,473,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wpnapps.dll
[2015/08/28 18:17:58 | 000,437,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Sensors.dll
[2015/08/28 18:17:58 | 000,373,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmkvsrcsnk.dll
[2015/08/28 18:17:58 | 000,333,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFPlay.dll
[2015/08/28 18:17:58 | 000,310,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsApi.dll
[2015/08/28 18:17:58 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieproxy.dll
[2015/08/28 18:17:58 | 000,285,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFPlay.dll
[2015/08/28 18:17:58 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2015/08/28 18:17:58 | 000,251,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsApi.dll
[2015/08/28 18:17:58 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fwpolicyiomgr.dll
[2015/08/28 18:17:58 | 000,163,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fwpolicyiomgr.dll
[2015/08/28 18:17:58 | 000,082,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcd.dll
[2015/08/28 18:17:57 | 011,557,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2015/08/28 18:17:57 | 009,889,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2015/08/28 18:17:57 | 006,305,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2015/08/28 18:17:57 | 004,760,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ExplorerFrame.dll
[2015/08/28 18:17:57 | 004,398,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2015/08/28 18:17:57 | 004,350,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ExplorerFrame.dll
[2015/08/28 18:17:57 | 004,169,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbon.dll
[2015/08/28 18:17:57 | 003,443,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbon.dll
[2015/08/28 18:17:57 | 002,147,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d9.dll
[2015/08/28 18:17:57 | 001,773,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Immersive.dll
[2015/08/28 18:17:57 | 001,611,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll
[2015/08/28 18:17:57 | 001,201,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Cred.dll
[2015/08/28 18:17:57 | 001,200,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpcrt4.dll
[2015/08/28 18:17:57 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorDataService.exe
[2015/08/28 18:17:57 | 000,872,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntshrui.dll
[2015/08/28 18:17:57 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2015/08/28 18:17:57 | 000,754,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Cred.dll
[2015/08/28 18:17:57 | 000,589,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uxtheme.dll
[2015/08/28 18:17:57 | 000,589,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\efscore.dll
[2015/08/28 18:17:57 | 000,584,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbonRes.dll
[2015/08/28 18:17:57 | 000,584,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbonRes.dll
[2015/08/28 18:17:57 | 000,584,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wimgapi.dll
[2015/08/28 18:17:57 | 000,542,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2015/08/28 18:17:57 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.BlockedShutdown.dll
[2015/08/28 18:17:57 | 000,414,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.BioFeedback.dll
[2015/08/28 18:17:57 | 000,407,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CredProvDataModel.dll
[2015/08/28 18:17:57 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\stobject.dll
[2015/08/28 18:17:57 | 000,335,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CredProvDataModel.dll
[2015/08/28 18:17:57 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.BlockedShutdown.dll
[2015/08/28 18:17:57 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConhostV2.dll
[2015/08/28 18:17:57 | 000,291,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\systemcpl.dll
[2015/08/28 18:17:57 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.BioFeedback.dll
[2015/08/28 18:17:57 | 000,279,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\systemcpl.dll
[2015/08/28 18:17:57 | 000,271,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConsoleLogon.dll
[2015/08/28 18:17:57 | 000,252,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ContentDeliveryManager.Utilities.dll
[2015/08/28 18:17:57 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DevicesFlowBroker.dll
[2015/08/28 18:17:57 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shutdownux.dll
[2015/08/28 18:17:57 | 000,181,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2015/08/28 18:17:57 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_SignInOptions.dll
[2015/08/28 18:17:57 | 000,179,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srumsvc.dll
[2015/08/28 18:17:57 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Privacy.dll
[2015/08/28 18:17:57 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sendmail.dll
[2015/08/28 18:17:57 | 000,104,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sendmail.dll
[2015/08/28 18:17:57 | 000,097,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcd.dll
[2015/08/28 18:17:57 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\spbcd.dll
[2015/08/28 18:17:57 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.ProxyStub.dll
[2015/08/28 18:17:57 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.OneCore.dll
[2015/08/28 18:17:57 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.PAL.Desktop.dll
[2015/08/28 18:17:57 | 000,045,568 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysNative\atmlib.dll
[2015/08/28 18:17:57 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\calc.exe
[2015/08/28 18:17:57 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\calc.exe
[2015/08/28 18:17:54 | 007,569,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mos.dll
[2015/08/28 18:17:54 | 007,051,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BingMaps.dll
[2015/08/28 18:17:54 | 006,101,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mos.dll
[2015/08/28 18:17:54 | 005,118,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\windows.storage.dll
[2015/08/28 18:17:54 | 005,076,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BingMaps.dll
[2015/08/28 18:17:54 | 003,362,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2015/08/28 18:17:54 | 001,591,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2015/08/28 18:17:54 | 001,521,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActiveSyncProvider.dll
[2015/08/28 18:17:54 | 001,420,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserDataService.dll
[2015/08/28 18:17:54 | 001,418,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RecoveryDrive.exe
[2015/08/28 18:17:54 | 001,417,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2015/08/28 18:17:54 | 001,294,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2015/08/28 18:17:54 | 001,203,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Unistore.dll
[2015/08/28 18:17:54 | 001,169,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dosvc.dll
[2015/08/28 18:17:54 | 001,135,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipUp.exe
[2015/08/28 18:17:54 | 001,123,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2015/08/28 18:17:54 | 001,018,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2015/08/28 18:17:54 | 000,934,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\refsv1.sys
[2015/08/28 18:17:54 | 000,925,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Unistore.dll
[2015/08/28 18:17:54 | 000,869,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapControlCore.dll
[2015/08/28 18:17:54 | 000,858,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2015/08/28 18:17:54 | 000,856,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ContactApis.dll
[2015/08/28 18:17:54 | 000,832,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapsStore.dll
[2015/08/28 18:17:54 | 000,783,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2015/08/28 18:17:54 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\efscore.dll
[2015/08/28 18:17:54 | 000,695,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimgapi.dll
[2015/08/28 18:17:54 | 000,654,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PlayToManager.dll
[2015/08/28 18:17:54 | 000,632,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2015/08/28 18:17:54 | 000,630,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2015/08/28 18:17:54 | 000,623,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ContactApis.dll
[2015/08/28 18:17:54 | 000,578,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winlogon.exe
[2015/08/28 18:17:54 | 000,521,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimserv.exe
[2015/08/28 18:17:54 | 000,494,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StoreAgent.dll
[2015/08/28 18:17:54 | 000,446,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapConfiguration.dll
[2015/08/28 18:17:54 | 000,430,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcomapi.dll
[2015/08/28 18:17:54 | 000,425,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2015/08/28 18:17:54 | 000,416,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2015/08/28 18:17:54 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuuhext.dll
[2015/08/28 18:17:54 | 000,359,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncsi.dll
[2015/08/28 18:17:54 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usocore.dll
[2015/08/28 18:17:54 | 000,342,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcastdvr.exe
[2015/08/28 18:17:54 | 000,329,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusUpdateHandlers.dll
[2015/08/28 18:17:54 | 000,328,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MapConfiguration.dll
[2015/08/28 18:17:54 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MBMediaManager.dll
[2015/08/28 18:17:54 | 000,290,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wininit.exe
[2015/08/28 18:17:54 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provhandlers.dll
[2015/08/28 18:17:54 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provengine.dll
[2015/08/28 18:17:54 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\updatehandlers.dll
[2015/08/28 18:17:54 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorService.dll
[2015/08/28 18:17:54 | 000,208,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2015/08/28 18:17:54 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srumsvc.dll
[2015/08/28 18:17:54 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmcsp.dll
[2015/08/28 18:17:54 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OmaDmAgent.dll
[2015/08/28 18:17:54 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReInfo.dll
[2015/08/28 18:17:54 | 000,187,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provisioningcsp.dll
[2015/08/28 18:17:54 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BootMenuUX.dll
[2015/08/28 18:17:54 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\psmsrv.dll
[2015/08/28 18:17:54 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdboot.exe
[2015/08/28 18:17:54 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storewuauth.dll
[2015/08/28 18:17:54 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotification.exe
[2015/08/28 18:17:54 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VEStoreEventHandlers.dll
[2015/08/28 18:17:54 | 000,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\omadmclient.exe
[2015/08/28 18:17:54 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsNativeApi.V2.dll
[2015/08/28 18:17:54 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spbcd.dll
[2015/08/28 18:17:54 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2015/08/28 18:17:54 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsNativeApi.V2.dll
[2015/08/28 18:17:54 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\setbcdlocale.dll
[2015/08/28 18:17:54 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\unenrollhook.dll
[2015/08/28 18:17:54 | 000,061,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dam.sys
[2015/08/28 18:17:54 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hmkd.dll
[2015/08/28 18:17:54 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotificationUx.exe
[2015/08/28 18:17:54 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\omadmprc.exe
[2015/08/28 18:17:54 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\hmkd.dll
[2015/08/28 18:17:54 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VoiceActivationManager.dll
[2015/08/28 18:17:54 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicenseManagerShellext.exe
  • ぐぬぬ
  • 2015/09/04 (Fri) 21:12:25
Re: DNSUnlockerの広告等々・・・
OTL 3/4

[2015/08/28 18:17:53 | 006,488,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\windows.storage.dll
[2015/08/28 18:17:53 | 004,611,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2015/08/28 18:17:53 | 003,248,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msftedit.dll
[2015/08/28 18:17:53 | 002,606,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msftedit.dll
[2015/08/28 18:17:53 | 002,125,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.appcore.dll
[2015/08/28 18:17:53 | 001,714,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.appcore.dll
[2015/08/28 18:17:53 | 001,203,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Bluetooth.dll
[2015/08/28 18:17:53 | 001,101,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2015/08/28 18:17:53 | 000,966,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.appcore.dll
[2015/08/28 18:17:53 | 000,841,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Import.dll
[2015/08/28 18:17:53 | 000,828,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Bluetooth.dll
[2015/08/28 18:17:53 | 000,823,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2015/08/28 18:17:53 | 000,808,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CoreMessaging.dll
[2015/08/28 18:17:53 | 000,762,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinapi.appcore.dll
[2015/08/28 18:17:53 | 000,680,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Connectivity.dll
[2015/08/28 18:17:53 | 000,679,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppContracts.dll
[2015/08/28 18:17:53 | 000,677,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2015/08/28 18:17:53 | 000,658,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipSVC.dll
[2015/08/28 18:17:53 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MessagingDataModel2.dll
[2015/08/28 18:17:53 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Import.dll
[2015/08/28 18:17:53 | 000,518,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationController.dll
[2015/08/28 18:17:53 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CoreMessaging.dll
[2015/08/28 18:17:53 | 000,503,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.Connectivity.dll
[2015/08/28 18:17:53 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MessagingDataModel2.dll
[2015/08/28 18:17:53 | 000,441,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppContracts.dll
[2015/08/28 18:17:53 | 000,421,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Bluetooth.dll
[2015/08/28 18:17:53 | 000,335,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wintrust.dll
[2015/08/28 18:17:53 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Internal.Bluetooth.dll
[2015/08/28 18:17:53 | 000,263,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DisplayManager.dll
[2015/08/28 18:17:53 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DisplayManager.dll
[2015/08/28 18:17:53 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmapi.dll
[2015/08/28 18:17:53 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ACPBackgroundManagerPolicy.dll
[2015/08/28 18:17:53 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbser.sys
[2015/08/28 18:17:53 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\bthhfenum.sys
[2015/08/28 18:17:53 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UcmUcsi.sys
[2015/08/28 18:17:53 | 000,037,376 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysWow64\atmlib.dll
[2015/08/28 18:17:53 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VoiceActivationManager.dll
[2015/08/28 18:17:53 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationControllerPS.dll
[2015/08/28 18:13:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\XPSViewer
[2015/08/28 18:13:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\msmq
[2015/08/28 18:13:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\BestPractices
[2015/08/28 18:13:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\BestPractices
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\inetpub
[2015/08/28 18:12:18 | 000,778,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationNative_v0300.dll
[2015/08/28 18:12:18 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2015/08/28 18:12:18 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TsWpfWrp.exe
[2015/08/28 18:12:14 | 001,166,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationNative_v0300.dll
[2015/08/28 18:12:14 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2015/08/28 18:12:14 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TsWpfWrp.exe
[2015/08/28 02:18:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2015/08/28 02:17:46 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Sun
[2015/08/28 02:17:44 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\.oracle_jre_usage
[2015/08/26 23:25:23 | 000,000,000 | ---D | C] -- C:\ProgramData\IntelDLM
[2015/08/26 23:19:58 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Intel
[2015/08/26 23:19:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver Update Utility
[2015/08/26 23:19:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel Driver Update Utility
[2015/08/26 23:19:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2015/08/26 23:12:52 | 005,069,632 | ---- | C] (Intel) -- C:\Users\【ユーザー名】\Desktop\Intel Driver Update Utility Installer.exe
[2015/08/24 17:24:39 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2015/08/24 17:24:39 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\MFAData
[2015/08/24 17:24:39 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2015/08/24 17:24:39 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Avg2015
[2015/08/22 23:38:49 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\The Last of Lolita escape
[2015/08/22 23:35:20 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\rushbattle
[2015/08/16 22:32:28 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\asunana-ver1-02
[2015/08/13 02:11:21 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MsSpellCheckingFacility.exe
[2015/08/13 02:11:18 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmlmedia.dll
[2015/08/13 02:11:13 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmlmedia.dll
[2015/08/13 02:04:57 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wu.upgrade.ps.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2015/09/04 20:14:15 | 000,016,148 | ---- | M] () -- C:\WINDOWS\SysNative\【ユーザー名】-PC_【ユーザー名】_HistoryPrediction.bin
[2015/09/04 20:08:56 | 000,000,714 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2015/09/04 20:07:00 | 000,000,626 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2015/09/04 19:37:55 | 001,926,466 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2015/09/04 19:37:55 | 000,890,860 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2015/09/04 19:37:55 | 000,631,044 | ---- | M] () -- C:\WINDOWS\SysNative\perfh011.dat
[2015/09/04 19:37:55 | 000,196,696 | ---- | M] () -- C:\WINDOWS\SysNative\perfc011.dat
[2015/09/04 19:37:55 | 000,196,668 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2015/09/04 19:35:30 | 000,000,710 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2015/09/04 19:35:23 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2015/09/04 19:33:52 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015/09/04 19:33:18 | 2076,831,743 | -HS- | M] () -- C:\hiberfil.sys
[2015/09/04 19:20:10 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2015/09/04 19:11:00 | 000,002,344 | ---- | M] () -- C:\Users\【ユーザー名】\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/09/04 19:11:00 | 000,002,320 | ---- | M] () -- C:\Users\【ユーザー名】\Desktop\Google Chrome.lnk
[2015/09/02 21:46:05 | 000,002,126 | ---- | M] () -- C:\Users\Public\Desktop\Acrobat Reader DC.lnk
[2015/09/02 21:27:18 | 000,002,154 | ---- | M] () -- C:\WINDOWS\SysNative\AutoRunFilter.ini
[2015/09/01 23:59:27 | 000,000,865 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015/08/31 16:11:39 | 000,000,085 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2015/08/30 22:49:47 | 000,001,345 | ---- | M] () -- C:\WINDOWS\SysNative\ServiceFilter.ini
[2015/08/29 02:31:45 | 000,000,242 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2015/08/29 02:30:00 | 000,406,152 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2015/08/28 20:08:32 | 009,898,752 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SysWow64\RsCRIcon.dll
[2015/08/28 20:08:32 | 000,410,880 | ---- | M] (Realsil Semiconductor Corporation) -- C:\WINDOWS\SysNative\drivers\RtsUer.sys
[2015/08/28 20:08:32 | 000,091,904 | ---- | M] (Realtek Semiconductor.) -- C:\WINDOWS\SysNative\RtCRX64.dll
[2015/08/28 20:06:45 | 000,599,240 | ---- | M] (Qualcomm Atheros) -- C:\WINDOWS\SysNative\drivers\btfilter.sys
[2015/08/28 20:06:45 | 000,182,784 | ---- | M] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll
[2015/08/28 20:06:45 | 000,011,264 | ---- | M] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll.muien-US
[2015/08/28 20:06:45 | 000,001,926 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0xf0.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x21.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x11.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40.dfu
[2015/08/28 20:06:45 | 000,001,922 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010100_40.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40_SS01.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40_nf01.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40.dfu
[2015/08/28 20:06:45 | 000,001,796 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020000_40.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_SS01.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_LV01.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0xf1.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x22.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x12.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,512 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010100_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,242 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,228 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x04.dfu
[2015/08/28 20:06:45 | 000,001,214 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x03.dfu
[2015/08/28 20:06:45 | 000,001,204 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2015/08/28 20:06:45 | 000,001,204 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40.dfu
[2015/08/28 20:06:45 | 000,001,198 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26.dfu
[2015/08/28 20:06:45 | 000,001,192 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26_0x01.dfu
[2015/08/28 20:06:45 | 000,000,296 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x01.dfu
[2015/08/28 20:06:45 | 000,000,278 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x04.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x03.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x02.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26_0x01.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26.dfu
[2015/08/28 20:06:44 | 000,246,804 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AtherosBT.bin
[2015/08/28 20:06:44 | 000,181,760 | ---- | M] (Qualcomm Atheros Communications Inc.) -- C:\WINDOWS\SysNative\btcoinst.dll
[2015/08/28 20:06:44 | 000,048,092 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020200.dfu
[2015/08/28 20:06:44 | 000,046,748 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010000.dfu
[2015/08/28 20:06:44 | 000,046,268 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020100.dfu
[2015/08/28 20:06:44 | 000,046,212 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020000.dfu
[2015/08/28 20:06:44 | 000,040,684 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010000_ss01.dfu
[2015/08/28 20:06:44 | 000,038,140 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010100.dfu
[2015/08/28 20:06:44 | 000,023,532 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020201.dfu
[2015/08/28 20:05:46 | 000,045,056 | ---- | M] () -- C:\WINDOWS\SysWow64\acovcnt.exe
[2015/08/28 19:01:20 | 000,010,449 | ---- | M] () -- C:\WINDOWS\diagerr.xml
[2015/08/28 19:01:20 | 000,009,528 | ---- | M] () -- C:\WINDOWS\diagwrn.xml
[2015/08/28 19:00:28 | 000,023,208 | ---- | M] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2015/08/28 18:33:07 | 001,667,602 | ---- | M] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2015/08/28 18:31:12 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01011.Wdf
[2015/08/28 18:30:46 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
[2015/08/28 18:18:06 | 001,561,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll
[2015/08/28 18:18:06 | 001,356,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll
[2015/08/28 18:18:06 | 000,569,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MCRecvSrc.dll
[2015/08/28 18:18:06 | 000,497,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToManager.dll
[2015/08/28 18:18:06 | 000,480,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MCRecvSrc.dll
[2015/08/28 18:18:06 | 000,275,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcastdvr.exe
[2015/08/28 18:17:58 | 014,241,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmp.dll
[2015/08/28 18:17:58 | 012,589,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmp.dll
[2015/08/28 18:17:58 | 004,791,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2015/08/28 18:17:58 | 003,248,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2015/08/28 18:17:58 | 002,646,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2015/08/28 18:17:58 | 001,562,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll
[2015/08/28 18:17:58 | 001,411,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Editing.dll
[2015/08/28 18:17:58 | 001,043,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Editing.dll
[2015/08/28 18:17:58 | 001,043,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2015/08/28 18:17:58 | 001,025,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsrcsnk.dll
[2015/08/28 18:17:58 | 000,980,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SecConfig.efi
[2015/08/28 18:17:58 | 000,896,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsrcsnk.dll
[2015/08/28 18:17:58 | 000,877,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2015/08/28 18:17:58 | 000,846,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpncore.dll
[2015/08/28 18:17:58 | 000,816,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmpeg2srcsnk.dll
[2015/08/28 18:17:58 | 000,799,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpccpl.dll
[2015/08/28 18:17:58 | 000,713,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
[2015/08/28 18:17:58 | 000,670,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieproxy.dll
[2015/08/28 18:17:58 | 000,599,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpnapps.dll
[2015/08/28 18:17:58 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Sensors.dll
[2015/08/28 18:17:58 | 000,527,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2015/08/28 18:17:58 | 000,521,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PsmServiceExtHost.dll
[2015/08/28 18:17:58 | 000,501,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2015/08/28 18:17:58 | 000,487,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmkvsrcsnk.dll
[2015/08/28 18:17:58 | 000,473,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wpnapps.dll
[2015/08/28 18:17:58 | 000,437,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Sensors.dll
[2015/08/28 18:17:58 | 000,373,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmkvsrcsnk.dll
[2015/08/28 18:17:58 | 000,333,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFPlay.dll
[2015/08/28 18:17:58 | 000,310,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsApi.dll
[2015/08/28 18:17:58 | 000,294,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieproxy.dll
[2015/08/28 18:17:58 | 000,285,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFPlay.dll
[2015/08/28 18:17:58 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2015/08/28 18:17:58 | 000,251,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsApi.dll
[2015/08/28 18:17:58 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fwpolicyiomgr.dll
[2015/08/28 18:17:58 | 000,163,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fwpolicyiomgr.dll
[2015/08/28 18:17:58 | 000,097,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcd.dll
[2015/08/28 18:17:58 | 000,082,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcd.dll
[2015/08/28 18:17:57 | 011,557,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2015/08/28 18:17:57 | 009,889,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2015/08/28 18:17:57 | 006,305,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2015/08/28 18:17:57 | 004,760,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ExplorerFrame.dll
[2015/08/28 18:17:57 | 004,398,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2015/08/28 18:17:57 | 004,350,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ExplorerFrame.dll
[2015/08/28 18:17:57 | 004,169,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbon.dll
[2015/08/28 18:17:57 | 003,443,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbon.dll
[2015/08/28 18:17:57 | 002,147,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d9.dll
[2015/08/28 18:17:57 | 001,773,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Immersive.dll
[2015/08/28 18:17:57 | 001,611,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll
[2015/08/28 18:17:57 | 001,201,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Cred.dll
[2015/08/28 18:17:57 | 001,200,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpcrt4.dll
[2015/08/28 18:17:57 | 001,031,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorDataService.exe
[2015/08/28 18:17:57 | 000,872,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntshrui.dll
[2015/08/28 18:17:57 | 000,850,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2015/08/28 18:17:57 | 000,754,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Cred.dll
[2015/08/28 18:17:57 | 000,589,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uxtheme.dll
[2015/08/28 18:17:57 | 000,589,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\efscore.dll
[2015/08/28 18:17:57 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbonRes.dll
[2015/08/28 18:17:57 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbonRes.dll
[2015/08/28 18:17:57 | 000,584,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wimgapi.dll
[2015/08/28 18:17:57 | 000,542,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2015/08/28 18:17:57 | 000,485,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.BlockedShutdown.dll
[2015/08/28 18:17:57 | 000,414,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.BioFeedback.dll
[2015/08/28 18:17:57 | 000,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CredProvDataModel.dll
[2015/08/28 18:17:57 | 000,356,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\stobject.dll
[2015/08/28 18:17:57 | 000,335,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CredProvDataModel.dll
[2015/08/28 18:17:57 | 000,322,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.BlockedShutdown.dll
[2015/08/28 18:17:57 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConhostV2.dll
[2015/08/28 18:17:57 | 000,291,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\systemcpl.dll
[2015/08/28 18:17:57 | 000,283,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.BioFeedback.dll
[2015/08/28 18:17:57 | 000,279,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\systemcpl.dll
[2015/08/28 18:17:57 | 000,271,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConsoleLogon.dll
[2015/08/28 18:17:57 | 000,252,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ContentDeliveryManager.Utilities.dll
[2015/08/28 18:17:57 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DevicesFlowBroker.dll
[2015/08/28 18:17:57 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shutdownux.dll
[2015/08/28 18:17:57 | 000,181,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2015/08/28 18:17:57 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_SignInOptions.dll
[2015/08/28 18:17:57 | 000,179,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srumsvc.dll
[2015/08/28 18:17:57 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Privacy.dll
[2015/08/28 18:17:57 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sendmail.dll
[2015/08/28 18:17:57 | 000,104,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sendmail.dll
[2015/08/28 18:17:57 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\spbcd.dll
[2015/08/28 18:17:57 | 000,068,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.ProxyStub.dll
[2015/08/28 18:17:57 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.OneCore.dll
[2015/08/28 18:17:57 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.PAL.Desktop.dll
[2015/08/28 18:17:57 | 000,045,568 | ---- | M] (Adobe Systems) -- C:\WINDOWS\SysNative\atmlib.dll
[2015/08/28 18:17:57 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\calc.exe
[2015/08/28 18:17:57 | 000,031,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\calc.exe
[2015/08/28 18:17:54 | 007,569,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mos.dll
[2015/08/28 18:17:54 | 007,051,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BingMaps.dll
[2015/08/28 18:17:54 | 006,101,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mos.dll
[2015/08/28 18:17:54 | 005,118,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\windows.storage.dll
[2015/08/28 18:17:54 | 005,076,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BingMaps.dll
[2015/08/28 18:17:54 | 003,362,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2015/08/28 18:17:54 | 001,591,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2015/08/28 18:17:54 | 001,521,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActiveSyncProvider.dll
[2015/08/28 18:17:54 | 001,420,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserDataService.dll
[2015/08/28 18:17:54 | 001,418,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RecoveryDrive.exe
[2015/08/28 18:17:54 | 001,417,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2015/08/28 18:17:54 | 001,294,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2015/08/28 18:17:54 | 001,203,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Unistore.dll
[2015/08/28 18:17:54 | 001,169,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dosvc.dll
[2015/08/28 18:17:54 | 001,135,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipUp.exe
[2015/08/28 18:17:54 | 001,123,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2015/08/28 18:17:54 | 001,018,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2015/08/28 18:17:54 | 000,934,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\refsv1.sys
[2015/08/28 18:17:54 | 000,925,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Unistore.dll
[2015/08/28 18:17:54 | 000,869,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapControlCore.dll
[2015/08/28 18:17:54 | 000,858,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2015/08/28 18:17:54 | 000,856,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ContactApis.dll
[2015/08/28 18:17:54 | 000,832,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapsStore.dll
[2015/08/28 18:17:54 | 000,783,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2015/08/28 18:17:54 | 000,752,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\efscore.dll
[2015/08/28 18:17:54 | 000,695,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimgapi.dll
[2015/08/28 18:17:54 | 000,654,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PlayToManager.dll
[2015/08/28 18:17:54 | 000,632,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2015/08/28 18:17:54 | 000,630,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2015/08/28 18:17:54 | 000,623,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ContactApis.dll
[2015/08/28 18:17:54 | 000,578,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winlogon.exe
[2015/08/28 18:17:54 | 000,521,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimserv.exe
[2015/08/28 18:17:54 | 000,505,344 | ---- | M] () -- C:\WINDOWS\SysNative\EditionUpgradeManagerObj.dll
[2015/08/28 18:17:54 | 000,494,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StoreAgent.dll
[2015/08/28 18:17:54 | 000,446,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapConfiguration.dll
[2015/08/28 18:17:54 | 000,430,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcomapi.dll
[2015/08/28 18:17:54 | 000,425,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2015/08/28 18:17:54 | 000,416,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2015/08/28 18:17:54 | 000,366,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuuhext.dll
[2015/08/28 18:17:54 | 000,359,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncsi.dll
[2015/08/28 18:17:54 | 000,343,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usocore.dll
[2015/08/28 18:17:54 | 000,342,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcastdvr.exe
[2015/08/28 18:17:54 | 000,329,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusUpdateHandlers.dll
[2015/08/28 18:17:54 | 000,328,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MapConfiguration.dll
[2015/08/28 18:17:54 | 000,303,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MBMediaManager.dll
[2015/08/28 18:17:54 | 000,290,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wininit.exe
[2015/08/28 18:17:54 | 000,287,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provhandlers.dll
[2015/08/28 18:17:54 | 000,268,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provengine.dll
[2015/08/28 18:17:54 | 000,242,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\updatehandlers.dll
[2015/08/28 18:17:54 | 000,229,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorService.dll
[2015/08/28 18:17:54 | 000,208,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2015/08/28 18:17:54 | 000,208,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srumsvc.dll
[2015/08/28 18:17:54 | 000,204,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmcsp.dll
[2015/08/28 18:17:54 | 000,204,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OmaDmAgent.dll
[2015/08/28 18:17:54 | 000,190,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReInfo.dll
[2015/08/28 18:17:54 | 000,187,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provisioningcsp.dll
[2015/08/28 18:17:54 | 000,186,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BootMenuUX.dll
[2015/08/28 18:17:54 | 000,185,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\psmsrv.dll
[2015/08/28 18:17:54 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdboot.exe
[2015/08/28 18:17:54 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storewuauth.dll
[2015/08/28 18:17:54 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotification.exe
[2015/08/28 18:17:54 | 000,144,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UMDF\SensorsCx.dll
[2015/08/28 18:17:54 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VEStoreEventHandlers.dll
[2015/08/28 18:17:54 | 000,120,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\omadmclient.exe
[2015/08/28 18:17:54 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsNativeApi.V2.dll
[2015/08/28 18:17:54 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spbcd.dll
[2015/08/28 18:17:54 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2015/08/28 18:17:54 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsNativeApi.V2.dll
[2015/08/28 18:17:54 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\setbcdlocale.dll
[2015/08/28 18:17:54 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\unenrollhook.dll
[2015/08/28 18:17:54 | 000,061,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dam.sys
[2015/08/28 18:17:54 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hmkd.dll
[2015/08/28 18:17:54 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotificationUx.exe
[2015/08/28 18:17:54 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\omadmprc.exe
[2015/08/28 18:17:54 | 000,045,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\hmkd.dll
[2015/08/28 18:17:54 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VoiceActivationManager.dll
[2015/08/28 18:17:54 | 000,032,768 | ---- | M] () -- C:\WINDOWS\SysNative\LicenseManagerApi.dll
[2015/08/28 18:17:54 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicenseManagerShellext.exe
[2015/08/28 18:17:53 | 006,488,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\windows.storage.dll
[2015/08/28 18:17:53 | 004,611,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2015/08/28 18:17:53 | 003,248,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msftedit.dll
[2015/08/28 18:17:53 | 002,606,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msftedit.dll
[2015/08/28 18:17:53 | 002,125,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.appcore.dll
[2015/08/28 18:17:53 | 001,714,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.appcore.dll
[2015/08/28 18:17:53 | 001,203,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Bluetooth.dll
[2015/08/28 18:17:53 | 001,101,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2015/08/28 18:17:53 | 000,966,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.appcore.dll
[2015/08/28 18:17:53 | 000,841,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Import.dll
[2015/08/28 18:17:53 | 000,828,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Bluetooth.dll
[2015/08/28 18:17:53 | 000,823,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2015/08/28 18:17:53 | 000,808,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CoreMessaging.dll
[2015/08/28 18:17:53 | 000,762,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinapi.appcore.dll
[2015/08/28 18:17:53 | 000,680,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Connectivity.dll
[2015/08/28 18:17:53 | 000,679,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppContracts.dll
[2015/08/28 18:17:53 | 000,677,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2015/08/28 18:17:53 | 000,658,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipSVC.dll
[2015/08/28 18:17:53 | 000,590,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MessagingDataModel2.dll
[2015/08/28 18:17:53 | 000,575,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Import.dll
[2015/08/28 18:17:53 | 000,518,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationController.dll
[2015/08/28 18:17:53 | 000,510,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CoreMessaging.dll
[2015/08/28 18:17:53 | 000,503,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.Connectivity.dll
[2015/08/28 18:17:53 | 000,465,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MessagingDataModel2.dll
[2015/08/28 18:17:53 | 000,441,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppContracts.dll
[2015/08/28 18:17:53 | 000,421,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Bluetooth.dll
[2015/08/28 18:17:53 | 000,335,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wintrust.dll
[2015/08/28 18:17:53 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Internal.Bluetooth.dll
[2015/08/28 18:17:53 | 000,263,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DisplayManager.dll
[2015/08/28 18:17:53 | 000,191,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DisplayManager.dll
[2015/08/28 18:17:53 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmapi.dll
[2015/08/28 18:17:53 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ACPBackgroundManagerPolicy.dll
[2015/08/28 18:17:53 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbser.sys
[2015/08/28 18:17:53 | 000,065,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\bthhfenum.sys
[2015/08/28 18:17:53 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UcmUcsi.sys
[2015/08/28 18:17:53 | 000,037,376 | ---- | M] (Adobe Systems) -- C:\WINDOWS\SysWow64\atmlib.dll
[2015/08/28 18:17:53 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VoiceActivationManager.dll
[2015/08/28 18:17:53 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationControllerPS.dll
[2015/08/28 18:13:02 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa.tlb
[2015/08/28 18:13:02 | 000,091,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa30.tlb
[2015/08/28 18:13:02 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa20.tlb
[2015/08/28 18:13:02 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa10.tlb
[2015/08/28 18:13:00 | 000,635,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqsnap.dll
[2015/08/28 18:13:00 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqcertui.dll
[2015/08/28 18:12:58 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iisRtl.dll
[2015/08/28 18:12:58 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\admwprox.dll
[2015/08/28 18:12:57 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ahadmin.dll
[2015/08/28 18:12:57 | 000,018,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iisreset.exe
[2015/08/28 18:12:57 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wamregps.dll
[2015/08/28 18:12:57 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iisrstap.dll
[2015/08/28 18:12:56 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\mqac.sys
[2015/08/28 18:12:55 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iisRtl.dll
[2015/08/28 18:12:55 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\admwprox.dll
[2015/08/28 18:12:54 | 000,229,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqrt.dll
[2015/08/28 18:12:54 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ahadmin.dll
[2015/08/28 18:12:54 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iisreset.exe
[2015/08/28 18:12:54 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wamregps.dll
[2015/08/28 18:12:54 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iisrstap.dll
[2015/08/28 18:12:52 | 000,265,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa.dll
[2015/08/28 18:12:52 | 000,009,096 | ---- | M] () -- C:\WINDOWS\SysWow64\msmqtrc.mof
[2015/08/28 18:12:51 | 000,130,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqlogmgr.dll
[2015/08/28 18:12:50 | 000,564,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqutil.dll
[2015/08/28 18:12:48 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa.tlb
[2015/08/28 18:12:48 | 000,091,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa30.tlb
[2015/08/28 18:12:48 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa20.tlb
[2015/08/28 18:12:48 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa10.tlb
[2015/08/28 18:12:46 | 000,813,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqsnap.dll
[2015/08/28 18:12:46 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqcertui.dll
[2015/08/28 18:12:45 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa.dll
[2015/08/28 18:12:45 | 000,009,096 | ---- | M] () -- C:\WINDOWS\SysNative\msmqtrc.mof
[2015/08/28 18:12:44 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqrt.dll
[2015/08/28 18:12:43 | 001,417,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqqm.dll
[2015/08/28 18:12:41 | 000,562,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqutil.dll
[2015/08/28 18:12:39 | 000,052,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqbkup.exe
[2015/08/28 18:12:39 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqsvc.exe
[2015/08/28 18:02:53 | 000,018,736 | -H-- | M] () -- C:\WINDOWS\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015/08/28 18:02:53 | 000,018,736 | -H-- | M] () -- C:\WINDOWS\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015/08/28 18:01:33 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2015/08/28 12:33:09 | 000,000,035 | ---- | M] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2015/08/28 02:17:24 | 000,097,888 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
[2015/08/27 03:33:05 | 000,007,607 | ---- | M] () -- C:\Users\【ユーザー名】\AppData\Local\Resmon.ResmonCfg
[2015/08/26 23:19:20 | 000,001,172 | ---- | M] () -- C:\Users\Public\Desktop\Intel(R) Driver Update Utility 2.2.lnk
[2015/08/26 23:18:58 | 005,069,632 | ---- | M] (Intel) -- C:\Users\【ユーザー名】\Desktop\Intel Driver Update Utility Installer.exe
[2015/08/20 15:07:55 | 008,019,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2015/08/20 15:06:53 | 000,609,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2015/08/20 14:57:13 | 000,077,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2015/08/20 14:26:23 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InstallAgent.exe
[2015/08/20 14:21:28 | 021,875,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2015/08/20 14:21:13 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EnterpriseModernAppMgmtCSP.dll
[2015/08/20 13:31:28 | 018,806,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2015/08/18 16:56:25 | 002,498,808 | ---- | M] () -- C:\WINDOWS\SysNative\CoreUIComponents.dll
[2015/08/18 16:55:45 | 000,373,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2015/08/18 16:54:30 | 001,396,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicenseManager.dll
[2015/08/18 16:27:23 | 001,771,592 | ---- | M] () -- C:\WINDOWS\SysWow64\CoreUIComponents.dll
[2015/08/18 16:24:35 | 000,963,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LicenseManager.dll
[2015/08/18 16:13:10 | 000,497,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WlanMediaManager.dll
[2015/08/18 16:13:06 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetSetupShim.dll
[2015/08/18 16:12:20 | 000,692,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UMDF\NfcCx.dll
[2015/08/18 16:12:18 | 002,225,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetworkMobileSettings.dll
[2015/08/18 16:04:20 | 000,859,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\modernexecserver.dll
[2015/08/18 16:04:14 | 001,234,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aitstatic.exe
[2015/08/18 15:59:35 | 001,294,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcnwiz.dll
[2015/08/18 15:59:02 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnApi.dll
[2015/08/18 15:58:46 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnNetsh.dll
[2015/08/18 15:58:34 | 000,112,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fdWCN.dll
[2015/08/18 15:58:31 | 000,117,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafWCN.dll
[2015/08/18 15:58:25 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetSetupSvc.dll
[2015/08/18 15:57:54 | 000,045,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wfdprov.dll
[2015/08/18 15:56:48 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BthRadioMedia.dll
[2015/08/18 15:55:01 | 002,178,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2015/08/18 15:54:11 | 000,247,296 | ---- | M] () -- C:\WINDOWS\SysNative\facecredentialprovider.dll
[2015/08/18 15:54:03 | 000,322,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vaultsvc.dll
[2015/08/18 15:52:26 | 001,888,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2015/08/18 15:50:04 | 001,795,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.dll
[2015/08/18 15:49:52 | 001,061,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\reseteng.dll
[2015/08/18 15:49:20 | 000,246,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PackageStateRoaming.dll
[2015/08/18 15:49:03 | 000,274,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\NetSetupShim.dll
[2015/08/18 15:36:08 | 001,226,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wcnwiz.dll
[2015/08/18 15:35:49 | 000,100,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WcnApi.dll
[2015/08/18 15:34:44 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wfdprov.dll
[2015/08/18 15:29:11 | 001,593,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2015/08/18 15:26:08 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PackageStateRoaming.dll
[2015/08/18 13:44:12 | 000,008,847 | ---- | M] () -- C:\WINDOWS\SysNative\ResPriHMImageList
[2015/08/16 23:03:02 | 000,000,571 | ---- | M] () -- C:\Users\【ユーザー名】\Desktop\あすなな.lnk
[2015/08/13 13:22:26 | 002,093,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidsvc.dll
[2015/08/13 13:20:39 | 000,414,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2015/08/13 12:53:21 | 000,311,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2015/08/11 19:04:24 | 002,462,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2015/08/11 19:04:23 | 004,532,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2015/08/11 19:04:15 | 001,087,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2015/08/11 19:03:09 | 000,442,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\storport.sys
[2015/08/11 19:02:57 | 000,554,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\directmanipulation.dll
[2015/08/11 19:02:56 | 000,080,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\stornvme.sys
[2015/08/11 19:02:49 | 000,292,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockAppHost.exe
[2015/08/11 18:52:49 | 000,993,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgent.dll
[2015/08/11 18:50:47 | 001,643,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diagtrack.dll
[2015/08/11 18:40:22 | 004,048,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2015/08/11 18:40:12 | 000,918,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2015/08/11 18:40:08 | 002,151,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2015/08/11 18:38:22 | 000,454,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\directmanipulation.dll
[2015/08/11 18:37:48 | 000,243,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LockAppHost.exe
[2015/08/11 18:26:03 | 000,845,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgent.dll
[2015/08/11 18:23:59 | 016,706,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2015/08/11 18:21:13 | 000,148,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tetheringservice.dll
[2015/08/11 18:21:04 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tetheringclient.dll
[2015/08/11 18:20:02 | 000,483,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OneDriveSettingSyncProvider.dll
[2015/08/11 18:19:45 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Notifications.dll
[2015/08/11 18:18:44 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserMgrProxy.dll
[2015/08/11 18:16:32 | 002,416,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2015/08/11 18:14:02 | 000,404,480 | ---- | M] () -- C:\WINDOWS\SysNative\diagtrack_wininternal.dll
[2015/08/11 18:13:42 | 000,413,184 | ---- | M] () -- C:\WINDOWS\SysNative\diagtrack_win.dll
[2015/08/11 18:11:40 | 002,446,336 | ---- | M] () -- C:\WINDOWS\SysNative\InputService.dll
[2015/08/11 18:11:18 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GamePanel.exe
[2015/08/11 18:10:47 | 000,293,376 | ---- | M] () -- C:\WINDOWS\SysNative\TextInputFramework.dll
[2015/08/11 18:10:12 | 000,324,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/08/11 18:10:06 | 000,778,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.dll
[2015/08/11 18:09:55 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuautoappupdate.dll
[2015/08/11 18:08:04 | 000,893,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApiPublic.dll
[2015/08/11 18:08:04 | 000,563,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApi.dll
[2015/08/11 18:07:52 | 000,593,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmsvc.dll
[2015/08/11 18:07:44 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeParserTask.exe
[2015/08/11 18:06:19 | 007,523,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2015/08/11 18:05:48 | 000,342,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationGeofences.dll
[2015/08/11 18:05:27 | 000,269,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationFramework.dll
[2015/08/11 18:05:23 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationFrameworkInternalPS.dll
[2015/08/11 18:05:20 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationPermissions.dll
[2015/08/11 18:05:10 | 000,996,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RDXService.dll
[2015/08/11 18:05:07 | 003,527,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tquery.dll
[2015/08/11 18:03:09 | 002,558,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssrch.dll
[2015/08/11 18:02:53 | 000,186,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cloudAP.dll
[2015/08/11 18:02:15 | 000,621,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enterprisecsps.dll
[2015/08/11 18:02:08 | 003,588,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2015/08/11 18:01:38 | 001,334,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIAutomationCore.dll
[2015/08/11 18:00:45 | 000,336,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchProtocolHost.exe
[2015/08/11 18:00:06 | 000,274,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\syncutil.dll
[2015/08/11 17:59:51 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssprxy.dll
[2015/08/11 17:59:33 | 000,042,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tetheringclient.dll
[2015/08/11 17:59:27 | 000,642,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdbui.dll
[2015/08/11 17:58:11 | 000,372,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\OneDriveSettingSyncProvider.dll
[2015/08/11 17:57:51 | 013,024,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2015/08/11 17:57:12 | 000,159,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserMgrProxy.dll
[2015/08/11 17:51:35 | 001,916,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2015/08/11 17:51:33 | 001,823,232 | ---- | M] () -- C:\WINDOWS\SysWow64\InputService.dll
[2015/08/11 17:50:59 | 000,131,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Core.TextInput.dll
[2015/08/11 17:50:58 | 000,200,704 | ---- | M] () -- C:\WINDOWS\SysWow64\TextInputFramework.dll
[2015/08/11 17:50:47 | 000,420,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GamePanel.exe
[2015/08/11 17:49:50 | 000,586,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
[2015/08/11 17:49:30 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/08/11 17:48:25 | 000,671,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApiPublic.dll
[2015/08/11 17:47:09 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApi.dll
[2015/08/11 17:43:39 | 002,748,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tquery.dll
[2015/08/11 17:42:33 | 005,454,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2015/08/11 17:40:32 | 001,964,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssrch.dll
[2015/08/11 17:40:12 | 001,112,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIAutomationCore.dll
[2015/08/11 17:38:43 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReInfo.dll
[2015/08/09 00:38:46 | 000,794,088 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2015/08/09 00:38:46 | 000,179,688 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
  • ぐぬぬ
  • 2015/09/04 (Fri) 21:13:59
Re: DNSUnlockerの広告等々・・・
OTL 4/4


[2015/08/08 16:29:58 | 001,822,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2015/08/08 16:19:45 | 000,608,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fontdrvhost.exe
[2015/08/08 15:48:13 | 000,539,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fontdrvhost.exe
[2015/08/08 15:40:23 | 000,365,056 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysNative\atmfd.dll
[2015/08/08 15:24:15 | 002,415,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2015/08/08 15:15:14 | 000,303,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\atmfd.dll
[2015/08/06 12:17:40 | 000,200,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wof.sys
[2015/08/06 11:22:03 | 000,685,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdiWiFi.sys

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2015/09/04 20:01:03 | 000,016,148 | ---- | C] () -- C:\WINDOWS\SysNative\【ユーザー名】-PC_【ユーザー名】_HistoryPrediction.bin
[2015/09/02 21:57:04 | 000,000,214 | ---- | C] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2015/09/02 21:46:05 | 000,002,457 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
[2015/09/02 21:46:05 | 000,002,126 | ---- | C] () -- C:\Users\Public\Desktop\Acrobat Reader DC.lnk
[2015/09/01 23:59:27 | 000,000,865 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015/08/31 16:11:33 | 000,000,085 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2015/08/29 15:48:34 | 002,498,808 | ---- | C] () -- C:\WINDOWS\SysNative\CoreUIComponents.dll
[2015/08/29 15:48:33 | 001,771,592 | ---- | C] () -- C:\WINDOWS\SysWow64\CoreUIComponents.dll
[2015/08/29 15:48:30 | 000,247,296 | ---- | C] () -- C:\WINDOWS\SysNative\facecredentialprovider.dll
[2015/08/29 15:48:30 | 000,008,847 | ---- | C] () -- C:\WINDOWS\SysNative\ResPriHMImageList
[2015/08/28 22:32:06 | 002,446,336 | ---- | C] () -- C:\WINDOWS\SysNative\InputService.dll
[2015/08/28 22:32:00 | 001,823,232 | ---- | C] () -- C:\WINDOWS\SysWow64\InputService.dll
[2015/08/28 22:31:59 | 000,404,480 | ---- | C] () -- C:\WINDOWS\SysNative\diagtrack_wininternal.dll
[2015/08/28 22:31:58 | 000,413,184 | ---- | C] () -- C:\WINDOWS\SysNative\diagtrack_win.dll
[2015/08/28 22:31:56 | 000,293,376 | ---- | C] () -- C:\WINDOWS\SysNative\TextInputFramework.dll
[2015/08/28 22:31:52 | 000,200,704 | ---- | C] () -- C:\WINDOWS\SysWow64\TextInputFramework.dll
[2015/08/28 20:08:40 | 000,002,271 | ---- | C] () -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
[2015/08/28 20:06:45 | 000,001,926 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0xf0.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x21.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x11.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40.dfu
[2015/08/28 20:06:45 | 000,001,922 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010100_40.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40_SS01.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40_nf01.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40.dfu
[2015/08/28 20:06:45 | 000,001,796 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020000_40.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_SS01.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_LV01.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0xf1.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x22.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x12.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,512 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010100_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,242 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,228 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x04.dfu
[2015/08/28 20:06:45 | 000,001,214 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x03.dfu
[2015/08/28 20:06:45 | 000,001,204 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2015/08/28 20:06:45 | 000,001,204 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40.dfu
[2015/08/28 20:06:45 | 000,001,198 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26.dfu
[2015/08/28 20:06:45 | 000,001,192 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26_0x01.dfu
[2015/08/28 20:06:45 | 000,000,296 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x01.dfu
[2015/08/28 20:06:45 | 000,000,278 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x04.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x03.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x02.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26_0x01.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26.dfu
[2015/08/28 20:06:44 | 000,246,804 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AtherosBT.bin
[2015/08/28 20:06:44 | 000,048,092 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020200.dfu
[2015/08/28 20:06:44 | 000,046,748 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010000.dfu
[2015/08/28 20:06:44 | 000,046,268 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020100.dfu
[2015/08/28 20:06:44 | 000,046,212 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020000.dfu
[2015/08/28 20:06:44 | 000,040,684 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010000_ss01.dfu
[2015/08/28 20:06:44 | 000,038,140 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010100.dfu
[2015/08/28 20:06:44 | 000,023,532 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020201.dfu
[2015/08/28 19:00:28 | 000,023,208 | ---- | C] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2015/08/28 18:48:21 | 000,001,576 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2015/08/28 18:34:27 | 000,000,352 | ---- | C] () -- C:\Users\【ユーザー名】\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2015/08/28 18:34:27 | 000,000,334 | ---- | C] () -- C:\Users\【ユーザー名】\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2015/08/28 18:33:12 | 001,926,466 | ---- | C] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2015/08/28 18:33:07 | 001,667,602 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2015/08/28 18:31:12 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01011.Wdf
[2015/08/28 18:30:46 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
[2015/08/28 18:26:01 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys
[2015/08/28 18:17:54 | 000,505,344 | ---- | C] () -- C:\WINDOWS\SysNative\EditionUpgradeManagerObj.dll
[2015/08/28 18:17:54 | 000,032,768 | ---- | C] () -- C:\WINDOWS\SysNative\LicenseManagerApi.dll
[2015/08/28 18:01:29 | 000,000,001 | -HS- | C] () -- C:\BOOTNXT
[2015/08/28 17:53:31 | 000,010,449 | ---- | C] () -- C:\WINDOWS\diagerr.xml
[2015/08/28 17:53:31 | 000,009,528 | ---- | C] () -- C:\WINDOWS\diagwrn.xml
[2015/08/26 23:19:20 | 000,001,172 | ---- | C] () -- C:\Users\Public\Desktop\Intel(R) Driver Update Utility 2.2.lnk
[2015/08/24 03:14:49 | 000,007,607 | ---- | C] () -- C:\Users\【ユーザー名】\AppData\Local\Resmon.ResmonCfg
[2015/08/16 23:03:02 | 000,000,571 | ---- | C] () -- C:\Users\【ユーザー名】\Desktop\あすなな.lnk
[2015/07/10 21:20:52 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2015/07/10 20:04:39 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2015/07/10 20:04:38 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2015/07/10 20:00:35 | 000,161,632 | ---- | C] () -- C:\WINDOWS\SysWow64\weretw.dll
[2015/07/10 20:00:33 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
[2015/07/10 20:00:32 | 000,047,104 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2015/07/10 20:00:31 | 000,156,672 | ---- | C] () -- C:\WINDOWS\SysWow64\MTF.dll
[2015/07/10 20:00:30 | 000,028,672 | ---- | C] () -- C:\WINDOWS\SysWow64\dtdump.exe
[2015/07/10 20:00:29 | 000,081,408 | ---- | C] () -- C:\WINDOWS\SysWow64\InputLocaleManager.dll
[2015/07/10 20:00:29 | 000,057,344 | ---- | C] () -- C:\WINDOWS\SysWow64\EditBufferTestHook.dll
[2015/07/10 20:00:29 | 000,053,760 | ---- | C] () -- C:\WINDOWS\SysWow64\WpKbdLayout.dll
[2015/07/10 20:00:29 | 000,022,016 | ---- | C] () -- C:\WINDOWS\SysWow64\WordBreakers.dll
[2015/07/10 20:00:28 | 000,270,848 | ---- | C] () -- C:\WINDOWS\SysWow64\HrtfApo.dll
[2015/07/10 20:00:27 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2015/07/10 20:00:26 | 000,022,528 | ---- | C] () -- C:\WINDOWS\SysWow64\efsext.dll
[2015/07/10 20:00:25 | 000,002,269 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2015/07/10 20:00:24 | 000,167,640 | ---- | C] () -- C:\WINDOWS\SysWow64\chs_singlechar_pinyin.dat
[2015/07/10 19:59:51 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2015/06/01 21:00:18 | 000,090,112 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll
[2015/06/01 19:46:58 | 000,272,928 | ---- | C] () -- C:\WINDOWS\SysWow64\igvpkrng600.bin
[2015/06/01 19:45:24 | 000,963,452 | ---- | C] () -- C:\WINDOWS\SysWow64\igcodeckrng600.bin
[2014/10/20 15:53:32 | 000,000,994 | ---- | C] () -- C:\Users\【ユーザー名】\.recently-used.xbel
[2012/03/02 16:35:16 | 000,000,242 | RHS- | C] () -- C:\ProgramData\ntuser.pol

[color=#E56717]========== ZeroAccess Check ==========[/color]


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\windows.storage.dll -- [2015/08/28 18:17:53 | 006,488,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\windows.storage.dll -- [2015/08/28 18:17:54 | 005,118,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2015/07/10 19:59:53 | 000,995,328 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2015/07/10 20:00:23 | 000,754,688 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2015/07/10 19:59:55 | 000,516,096 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Custom Scans ==========[/color]
[2012/05/30 14:11:23 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2015/09/03 21:37:50 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2015/08/29 03:07:20 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2012/04/17 10:54:47 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\CSharp
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\csharp-shared
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\MCpp
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\VBasic
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\vbasic-shared
[2012/05/30 14:54:59 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\VCATL
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\vcatl-shared
[2015/09/04 19:39:26 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsApps
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ
[2015/08/24 17:24:39 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ\IJPrinter
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ\IJPrinter\CNMWindows
[2013/04/08 13:41:08 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ\IJPrinter\CNMWindows\Canon MP980 series Printer
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc
[2015/07/10 21:21:42 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2015/07/11 01:34:34 | 000,000,000 | RH-D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\DMProfiles
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\Profiles
[2015/08/28 19:01:56 | 000,000,000 | RH-D | M] -- C:\Users\Default
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonBJ
[2015/08/24 17:24:39 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Common Files
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonBJ\IJPrinter
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonBJ\IJPrinter\CNMWindows
[2013/04/08 13:41:08 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonBJ\IJPrinter\CNMWindows\Canon MP980 series Printer
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc
[2015/07/10 21:21:42 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2015/07/11 01:34:34 | 000,000,000 | RH-D | M] -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Tablet PC
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\DMProfiles
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\Profiles
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\Users\Default\AppData
[2015/08/31 16:16:07 | 000,000,000 | RH-D | M] -- C:\Users\Public\AccountPictures
[2015/09/04 19:30:27 | 000,000,000 | RH-D | M] -- C:\Users\Public\Desktop
[2009/07/14 11:34:59 | 000,000,000 | RH-D | M] -- C:\Users\Public\Favorites
[2015/08/28 19:00:10 | 000,000,000 | RH-D | M] -- C:\Users\Public\Libraries
[2015/08/28 18:36:06 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData
[2015/08/28 20:08:18 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~
[2012/05/30 00:26:41 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~
[2015/08/28 20:08:01 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\Windows\INetCache\Virtualized
[2015/08/28 20:03:10 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\Windows\INetCookies\PrivacIE\Low
[2015/01/22 15:35:30 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\VirtualStore\ProgramData
[2015/08/28 18:57:16 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2015/07/10 20:04:27 | 000,000,000 | -H-D | M] -- C:\Windows\ELAMBKUP
[2015/08/28 18:42:27 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData
[2015/08/28 22:48:34 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData
[2015/08/28 18:36:39 | 000,000,000 | -H-D | M] -- C:\WINDOWS\SysNative\GroupPolicy

[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2015/09/04 20:07:00 | 000,000,626 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2015/09/04 19:20:10 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2015/09/04 19:35:30 | 000,000,710 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2015/09/04 20:08:56 | 000,000,714 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[color=#E56717]========== Drive Information ==========[/color]

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: Hitachi HTS547575A9E384
Partitions: 3
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 25.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 279.00GB
Starting Offset: 26844594176
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 394.00GB
Starting Offset: 326906150912
Hidden sectors: 0


[color=#E56717]========== Base Services ==========[/color]
No service found with a name of AeLookupSvc
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,093,696 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,097,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 001,168,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,794,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,096,256 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV - [2015/07/10 20:00:27 | 000,069,632 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,472,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2015/07/10 20:00:26 | 000,344,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:39 | 000,133,120 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,077,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,873,984 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,356,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2015/07/10 20:00:30 | 000,292,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,276,992 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:52 | 000,106,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (Eaphost)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,034,304 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2015/07/10 20:00:26 | 000,029,696 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,452,608 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:52 | 000,390,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:[b]64bit:[/b] - [2015/07/10 19:59:55 | 000,464,896 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
No service found with a name of MMCSS
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,265,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,550,400 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:09 | 000,371,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,029,184 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:57 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:14 | 000,781,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
No service found with a name of ProtectedStorage
No service found with a name of EMDMgmt
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,106,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:51 | 000,679,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,873,984 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,056,344 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:09 | 000,179,200 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,283,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:19 | 000,593,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2015/07/10 20:00:33 | 000,544,768 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:[b]64bit:[/b] - [2015/08/03 10:22:29 | 001,008,640 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:14 | 000,311,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2015/07/10 20:00:32 | 000,254,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:17 | 000,058,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,324,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 001,370,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:58 | 001,067,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (Audiosrv)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:58 | 000,280,064 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:09 | 000,150,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,024,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:54 | 001,729,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (EventLog)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,856,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:10 | 000,637,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\msiexec.exe -- (msiserver)
SRV - [2015/08/28 18:17:57 | 000,058,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysWow64\msiexec.exe -- (msiserver)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:[b]64bit:[/b] - [2015/08/20 14:13:54 | 002,235,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,263,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:[b]64bit:[/b] - [2015/08/18 16:07:34 | 002,226,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (WlanSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,279,040 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

< End of report >
  • ぐぬぬ
  • 2015/09/04 (Fri) 21:15:13
Re: DNSUnlockerの広告等々・・・
Extras 1/1

OTL Extras logfile created on: 2015/09/04 20:08:22 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\【ユーザー名】\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.10240.16384)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.91 Gb Total Physical Memory | 5.97 Gb Available Physical Memory | 75.41% Memory free
15.91 Gb Paging File | 14.01 Gb Available in Paging File | 88.07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.45 Gb Total Space | 211.00 Gb Free Space | 75.50% Space Free | Partition Type: NTFS
Drive D: | 394.18 Gb Total Space | 393.85 Gb Free Space | 99.92% Space Free | Partition Type: NTFS

Computer Name: 【ユーザー名】-PC | User Name: 【ユーザー名】 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3922431837-200563891-1274897566-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = EF EB 54 8B 78 E1 D0 01 [binary data]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = A7 74 5E 8B 78 E1 D0 01 [binary data]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{76AA7345-9C0C-4120-9466-C2FDE56D431D}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{A285F19E-0391-45DA-ADAD-CA76B8D275D8}" = lport=4588 | protocol=6 | dir=in | app=c:\windows\syswow64\config\systemprofile\appdata\local\windows internet name service\wins.exe |
"{A2A9038D-9E61-4895-BECE-69CB8DD424A2}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{AF476326-0765-4093-BA93-24AB3654A843}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B0052AB6-FEB8-4ECD-B4AD-286048092ED0}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B36EC7EF-8809-4BED-82B4-F3C0DCD5DD2E}" = lport=4588 | protocol=17 | dir=in | app=c:\windows\syswow64\config\systemprofile\appdata\local\windows internet name service\wins.exe |
"{BE63DC2A-9A55-4D85-9816-E8FA7B68C34C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{D9C54D23-CDC7-446F-9F7B-E9FB14FE76C3}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01A08150-3650-40C9-9C68-FE9E8870DF65}" = dir=out | name=@{microsoft.appconnector_1.3.3.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.appconnector/resources/connectorstubtitle} |
"{024C1651-1E4E-4995-A4E8-3CDEC95AB115}" = dir=out | name=candy crush saga |
"{0420B7F2-1900-4F5F-A9A2-FF428661DE38}" = dir=out | name=@{microsoft.windows.cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} |
"{048ACAEE-9E2C-4F68-ACFD-8DF57D1D0EA4}" = dir=in | name=@{microsoft.bingweather_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} |
"{05BD945B-5851-4454-9C06-28F19BB84D51}" = dir=out | name=@{microsoft.lockapp_10.0.10240.16384_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{08E2AD17-626B-4300-B19D-EC3F6186A984}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{0B65E9B1-F492-43FF-8574-4079597F135E}" = dir=out | name=@{windows.contactsupport_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{14A7006E-84CC-427C-B167-8C674BF1A246}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{1782C34A-6693-4C1B-9E00-636D0148DFF4}" = dir=out | name=@{microsoft.bingnews_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} |
"{1C9402F3-EE6B-4551-9209-B4E4D37CEB3E}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} |
"{23D7E189-14A1-4012-834D-75F2CEA6F16B}" = dir=out | name=@{microsoft.bingsports_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} |
"{37F6997D-6416-486C-83F5-ED1CCB98F302}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.6121.42001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/appmanifest_outlookdesktop_displayname} |
"{387B5133-C741-40C2-8F3A-4797C3555EC7}" = dir=in | name=@{microsoft.bingnews_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} |
"{3D43F6DC-B7A3-45C7-8142-C02C9B9FF887}" = dir=in | name=@{microsoft.microsoftedge_20.10240.16384.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{41D207C8-98B9-4CCC-9BE9-BB01043676D1}" = dir=out | name=@{microsoft.bingfinance_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} |
"{46F3C9B3-A2C5-420E-879D-BD41C09A9EC1}" = dir=in | name=microsoft solitaire collection |
"{49EA16CD-4131-4C2D-877C-43069627103A}" = dir=out | name=microsoft solitaire collection |
"{4ADF2CB4-E84B-406C-9CA8-27E0D247D82B}" = dir=out | name=@{microsoft.xboxidentityprovider_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxidentityprovider/resources/pkgdisplayname} |
"{4AEC336B-2FC0-46BA-A428-78720500DE69}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{50D1D736-D8D0-4CCB-AAFE-DD76182D5990}" = dir=out | app=c:\windows\syswow64\config\systemprofile\appdata\local\windows internet name service\wins.exe |
"{5B07B081-3A86-4AA0-966F-E3874376B51A}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{611E2C49-1ABD-4623-8A08-FB5CE707E1AA}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} |
"{6B57533C-3565-4F3A-A9A5-FA09A0E12B22}" = dir=out | name=@{microsoft.windowsstore_2015.8.25.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} |
"{75021B4F-0AB5-4187-BC7B-B1D72705D027}" = dir=out | name=@{microsoft.people_1.10241.0.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.people/resources/appstorename} |
"{79AF7BA8-F8C3-4322-8070-97648D60371B}" = dir=in | name=xbox |
"{7C773E52-11FA-4E10-BE8C-D7D6F7F38812}" = dir=out | name=onenote |
"{7CEB8E30-B5CE-4B54-9C41-DC5160A5869F}" = dir=out | name=xbox |
"{7FA27206-9E4E-4C15-B1C4-1D249AF6CF51}" = dir=out | name=@{microsoft.accountscontrol_10.0.10240.16384_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} |
"{860C11BF-52A5-4C18-85CE-49CF9EE20D49}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{873E866F-A086-4F34-A901-5D9749C32944}" = dir=in | name=onenote |
"{87B1ACF4-78F4-4B21-ABB1-E7491E32847A}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{8FA1C735-FAA0-4259-9A32-365CFC3D437D}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{90F73B26-A738-4B53-AA39-1018E2795BA6}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{96A6C57A-22F9-4408-8294-516785961995}" = dir=out | name=@{microsoft.windowsmaps_4.1507.50821.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsmaps/resources/appstorename} |
"{989145A7-7601-4D14-A21B-05991D4C61CE}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{AAD18B19-3E54-480C-95BA-5D2818FA3C27}" = dir=out | name=@{microsoft.windowsfeedback_10.0.10240.16393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windowsfeedback/feedbackapp.resources/appname/text} |
"{ACBCF777-199F-45EE-835B-79E6FF1E23D0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{B34C2383-3D7E-422D-B281-230DA69038D8}" = dir=out | name=@{microsoft.microsoftedge_20.10240.16384.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{B6F0DD56-C5B0-438A-976D-37D2BD93CF50}" = dir=out | name=@{microsoft.zunevideo_3.6.12711.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{BA4A7DA8-7697-4C3D-969D-D9525BF1223D}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{C1C34168-055B-4D77-9240-D2228C749AF7}" = dir=out | name=@{microsoft.windowsdvdplayer_3.6.11761.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsdvdplayer/resources/ids_dvdplayer_app_name} |
"{C1E1E3A9-8B60-4EC9-9699-7F989485B0FB}" = dir=in | name=@{microsoft.windowsstore_2015.8.25.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} |
"{C470B818-7B32-43D2-B56E-5978BB8800D4}" = dir=in | name=@{microsoft.windows.cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} |
"{C50307A9-B950-40ED-AC31-603BA9FE7075}" = dir=out | name=twitter |
"{C791AD11-F480-438F-BF97-573479593162}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.6121.42001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/appmanifest_outlookdesktop_displayname} |
"{D3BF01FA-5ADC-481F-8F6D-ED6F5A96A9E0}" = dir=out | name=@{microsoft.windowsphone_10.1508.17010.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphone/resources/appstorename} |
"{DA75C6AA-2E96-438A-AEDB-BBB40AE7AAE8}" = dir=out | name=@{microsoft.getstarted_2.3.4.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.getstarted/resources/appstorename} |
"{DBA2C57F-7029-49F5-A2C2-B21BB16D7667}" = dir=out | name=@{windows.purchasedialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.purchasedialog/resources/displayname} |
"{E2B7FD3A-4046-4C19-B1B0-C25A50549D1B}" = dir=in | name=@{microsoft.bingsports_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} |
"{E4D759F5-D3F9-4677-A580-F445FBD27508}" = dir=in | name=@{microsoft.bingfinance_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} |
"{E7BEB7B9-D48E-431C-992A-2D7F474B97FA}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{EEF661ED-8FCB-4224-9F31-09BAA674C60D}" = dir=in | name=@{windows.contactsupport_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{F09E0A8E-9530-44DF-8108-55C08720266A}" = dir=in | name=@{microsoft.microsoftofficehub_17.6121.23761.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} |
"{F637DEDD-E82F-4B96-9489-04335FDD3EB2}" = dir=out | name=windows_ie_ac_001 |
"{F6C7757E-E430-4290-8BCB-3F91A63977E9}" = dir=in | name=@{microsoft.windows.photos_15.827.16340.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} |
"{F735331E-926B-4B62-9693-F7479E532AA9}" = dir=out | name=@{microsoft.zunemusic_3.6.12711.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{F8340D5B-B333-4B63-9484-FC5F0975E0C8}" = dir=out | name=@{microsoft.3dbuilder_10.1.9.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.3dbuilder/resources/appstorename} |
"{F8A2AB89-82DA-4588-A798-C01438CF1423}" = dir=out | name=@{microsoft.microsoftofficehub_17.6121.23761.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} |
"{F92A7A2F-0074-48DF-9FA2-899A1DF74C35}" = dir=out | name=@{microsoft.bingweather_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} |
"{F998889C-B750-4B1D-A191-278EC416E8A3}" = dir=out | name=@{microsoft.windows.photos_15.827.16340.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0EE529F2-2742-494B-ACF5-2C68D82B8AFE}" = Windows Live Family Safety
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1AAF6669-31B2-3840-9346-F0F653840FD1}" = Microsoft .NET Framework 4.5.1 (JPN)
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{20752CA6-889D-4EBC-9392-929B4CFE3302}" = Microsoft SQL Server 2008 R2 管理オブジェクト (x64)
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
"{26784146-6E05-3FF9-9335-786C7C0FB5BE}" = Microsoft .NET Framework 4.5.2
"{2AAB9867-958C-4446-A66E-D5F52B736F99}" = Microsoft SQL Server 2008 Database Engine Shared
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{33B98264-A889-4913-A0CA-C364A75032B3}" = ASUS Power4Gear Hybrid
"{3AF674EE-1A2E-469B-88AC-E867CDB33D99}" = Microsoft SQL Server 2008 Native Client
"{3BF2C0A8-2C44-4A36-AA96-3BD6FB7BB01F}" = Windows Live Remote Client Resources
"{42407101-F6C1-3B67-AA7E-613FEC717081}" = Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319
"{4F5A98E0-2801-463C-8166-276FCB775980}" = Microsoft SQL Server System CLR Types (x64)
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{54C5B89F-0A8C-4C07-A51D-7380974DA459}" = Windows Live Remote Service Resources
"{5CA7FC9B-8508-4494-B365-6FBCBAEB8E89}" = Intel(R) Chipset Device Software
"{5DA6F56A-5E2D-4FB4-88CB-E9EE2B790A14}" = Microsoft SQL Server Compact 3.5 SP2 x64 JPN
"{616124A1-E9D8-3FC3-87E9-D906779F4765}" = Microsoft Team Foundation Server 2010 Object Model - JPN
"{61F2BDE9-816B-4BE6-AD63-0C349C2348CA}" = Microsoft Sync Framework Runtime v1.0 SP1 (x64) ja
"{761C6783-D3BC-48AB-8E7C-61CE918A8436}" = ASUS Secure Delete
"{8137177F-FA3A-4A90-B6A5-8CD066008EEF}" = Microsoft SQL Server VSS Writer
"{81455DEB-FC7E-3EE5-85CA-2EBDD9FD61EB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-0028-0411-1000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2010
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0411-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Japanese) 2010
"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{986E003C-E56D-5A47-110E-D3C81F0E8535}" = Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.11761.0_neutral_~_8wekyb3d8bbwe (x64)
"{A25A8788-0D02-4FC7-B7F7-C80DD7251FE3}" = Microsoft SQL Server 2008 Common Files
"{A2E3EA10-074E-4D8C-BDC8-69BFC7699ACE}" = Microsoft Sync Framework Services v1.0 SP1 (x64) ja
"{AC04591A-A74F-44C3-936A-D294C9D135C6}" = Microsoft SQL Server 2008 Database Engine Services
"{ADBD6E65-46CB-4A97-9AFB-64963FEACC40}" = Microsoft SQL Server 2008 RsFx Driver
"{B0E40F1B-713D-3F68-840C-23262E34BDB4}" = Microsoft Help Viewer 1.1 Language Pack - JPN
"{B41AFA7D-B721-4B6C-ACEA-4DC946F482B0}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) ja
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = インテル(R) ターボ・ブースト・テクノロジー・モニター 2.0
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{D2837730-4960-3B35-8088-201387FD3BDB}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - JPN
"{D57519D3-2E37-3E34-94AF-4D59BFAB87E6}" = Microsoft Visual Studio 2010 Office Developer Tools (x64)
"{D9FCBAAE-DB72-488B-96D0-0AA3C892C0D6}" = Microsoft Security Client
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E31AD2E7-7018-4085-88B0-3FFCCF8AE9C9}" = Microsoft DirectX 9.0 Developer Runtime for x64
"{E4F4D532-3BAF-3B8C-A395-0911AC0B0DFE}" = Microsoft Visual Studio 2010 Office Developer Tools (x64) Language Pack - JPN
"{E5748D30-7E6D-3A8E-BFE6-C1D02C6DDABB}" = Microsoft Help Viewer 1.1
"{EC13D94D-B308-3C76-81CB-89386AEE18D7}" = Visual Studio 2010 Prerequisites - English
"{F43ADE73-2880-4A95-B995-4FE386ECF667}" = Microsoft SQL Server 2008 Setup Support Files
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-X64 8.0.5.3_WHQL
"Lhaz" = Lhaz
"Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1
"Microsoft Help Viewer 1.1 Language Pack - JPN" = Microsoft Help Viewer 1.1 Language Pack - JPN
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"Microsoft Team Foundation Server 2010 Object Model - JPN" = Microsoft Team Foundation Server 2010 オブジェクト モデル - 日本語
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - JPN" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0044AEC7-8924-4FB1-B4F7-FD14A5FEA9E4}" = RPGツクール2003 ランタイムパッケージ
"{014A2868-BE56-4888-A16C-693989B8F153}" = SlimDX Runtime .NET 2.0 (January 2012)
"{019EF473-6D0A-415C-9A2E-1AF5F66AC60F}" = Windows Live Messenger
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}" = Sonic Focus
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{10AB1F40-BDEC-4A8D-B427-30F9429378B0}" = Windows Live Movie Maker
"{12176DDA-76A7-41AC-9C37-78D662C0FC2B}" = Dotfuscator Software Services - Community Edition - JPN
"{15D95497-8F76-41E5-8894-EDDB59E39BD9}" = Windows Live メール
"{15DF7630-7E1A-4DD1-A964-2B8F253FE05C}" = Microsoft SQL Server 2008 Browser
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1AA5BD63-6614-44B2-88A7-605191EDB835}" = Dotfuscator Software Services - Community Edition
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83218060F0}" = Java 8 Update 60
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{2F2E6B20-C46E-338E-AD50-310CDCB01507}" = Microsoft Visual Studio 2010 Professional - JPN
"{2F8B731A-5F2D-3EA8-8B25-C3E5E43F4BDB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33F7A957-A66D-45A1-BADF-6576083B14E2}" = RPGツクール2000 ランタイムパッケージ
"{38636216-B3E8-4A73-B5F4-D00A4A290650}" = Microsoft Silverlight 4 SDK - 日本語
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3EE9923D-3045-46AB-9CAA-E375993AEB4A}" = Intel(R) Driver Update Utility 2.2
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5172E572-C175-4F80-A6D5-5CB45826AD61}" = SceneSwitch
"{536DD37D-90EE-41DB-AEAA-ED9AA7488714}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 JPN
"{5AB776A5-8116-37FC-9788-C3E80E2AC1D4}" = Microsoft Visual F# 2.0 Runtime Language Pack - 日本語
"{5AB7D739-1735-3A9E-BE73-C43507CB4E6F}" = Microsoft Visual Studio 2010 Service Pack 1
"{5BA92669-B090-4767-9ED6-8D4F9B89DFAB}" = Microsoft SQL Server 2008 R2 データ層アプリケーション フレームワーク
"{5D757758-65D1-33E0-894F-A417D43B1B38}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{62BBB2F0-E220-4821-A564-730807D2C34D}" = Realtek USB 2.0 Reader Driver
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65E40D94-5C26-49CA-925F-8010E61D5F6C}" = Microsoft SQL Server 2008 R2 データ層アプリケーション プロジェクト
"{675D8E1E-2388-4718-902C-E5FC4888AC0E}" = Windows Live Essentials
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C3F8916-D6A5-4A31-9DA8-80C973CE437F}" = Windows Live Writer
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7134EF35-DA07-41F8-A71F-66709E194BB5}" = Windows Live Mesh
"{749F674B-2674-47E8-879C-5626A06B2A91}" = InstantOn for NB
"{7ADAC5B9-BAD3-37AF-A07D-D97847FF5D33}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{7C056FA6-E362-467B-8160-062E9474FEE5}" = SlimDX Redistributable for .NET 2.0 (September 2011)
"{8150221C-8F7E-4997-AD4E-AFDEE7F4B410}" = Wireless Console 3
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{85467CBC-7A39-33C9-8940-D72D9269B84F}" = Microsoft Visual F# 2.0 Runtime
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{88A686A9-D687-4295-B633-50D8A4B88371}" = Windows Live Writer Resources
"{89E9AB79-7914-4B67-8D4E-A8B1E39C3D89}" = Microsoft SQL Server Compact 3.5 SP2 JPN
"{8A66A2C8-0032-4949-8D99-C293A3EACF79}" = Windows Live Photo Common
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D59BE38-3A4F-4525-AD0D-8980E9E31EFA}" = Windows Live フォト ギャラリー
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0411-0000-0000000FF1CE}" = Microsoft Office Access MUI (Japanese) 2010
"{90140000-0016-0411-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Japanese) 2010
"{90140000-0018-0411-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Japanese) 2010
"{90140000-0019-0411-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Japanese) 2010
"{90140000-001A-0411-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Japanese) 2010
"{90140000-001B-0411-0000-0000000FF1CE}" = Microsoft Office Word MUI (Japanese) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0411-0000-0000000FF1CE}" = Microsoft Office Proof (Japanese) 2010
"{90140000-0028-0411-0000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2010
"{90140000-002C-0411-0000-0000000FF1CE}" = Microsoft Office Proofing (Japanese) 2010
"{90140000-0044-0411-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Japanese) 2010
"{90140000-006E-0411-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Japanese) 2010
"{90140000-00A1-0411-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Japanese) 2010
"{90140000-00BA-0411-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Japanese) 2010
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97C08405-B93D-44D9-B850-56B63C4936B8}" = Microsoft SQL Server 2008 R2 Transact-SQL 言語サービス
"{98f335cd-0a32-4b3f-b74c-ef9480e834f0}" = インテル® チップセット デバイス ソフトウェア
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A74A0091-5290-4EB8-B708-11AAA1BCEA6B}" = Microsoft SQL Server System CLR Types
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio
"{AC76BA86-0804-1033-1959-001824147215}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1041-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Japanese
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{AECA3622-E634-4A55-A696-70A511CBE06E}" = ASUS USB Charger Plus
"{B2DB883F-1AF3-4BE6-BE04-710D9C556C44}" = PowerWiz
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR
"{BAF0CA91-4642-46C8-9BCD-C93B61508701}" = リモート接続用の Windows Live Mesh ActiveX コントロール (日本語)
"{BF01E39C-5B68-4AD8-8DF1-9A37356D43F4}" = Microsoft SQL Server 2008 R2 管理オブジェクト
"{C0C7C6B3-4172-4296-ABFD-C176AE8FA1D2}" = Microsoft Silverlight 3 SDK - 日本語
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{ca4bc3a8-b99c-4416-90d8-351a8ceab458}" = Intel Driver Update Utility
"{CCB6898B-6470-417C-A0EE-DB7485E73A26}" = Microsoft Sync Framework SDK v1.0 SP1 ja
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D39F0676-163E-4595-A917-E28F99BBD4D2}" = ASUS AI Recovery
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}" = WCF RIA Services V1.0 SP1
"{DAD74137-2B54-4434-9630-B5DF176F5D3A}" = Microsoft ASP.NET MVC 2 - JPN
"{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}" = Microsoft ASP.NET MVC 2
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E764C46D-C726-403B-9874-4E35F2CACDBE}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - JPN
"{E80A8B4A-0CAF-3AD8-8A7E-74B4CC5A07DC}" = Microsoft Visual Studio Macro Tools - JPN Language Pack
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (October 2004)
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{EE03B0F1-7579-4CDD-BA63-BA37A8B9E2DB}" = Microsoft DirectX 9.0 SDK Update (October 2004)
"{EE408577-9C0E-4E5F-BCB2-DB5B3A220958}" = Windows Live UX Platform Language Pack
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F76E8352-DB67-4B74-8C77-C0C040F7D642}" = Prominence
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ASUS WebStorage" = ASUS WebStorage
"AsusScr_U_24_Series_ENG" = AsusScr_U_24_Series_ENG
"Google Chrome" = Google Chrome
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"MetasequoiaLE R3,0" = MetasequoiaLE R3.0
"Microsoft Visual Studio 2010 Professional - JPN" = Microsoft Visual Studio 2010 Professional - 日本語
"Microsoft Visual Studio 2010 Service Pack 1" = Microsoft Visual Studio 2010 Service Pack 1
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Microsoft Visual Studio Macro Tools - JPN Language Pack" = Microsoft Visual Studio Macro Tools - JPN Language Pack
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Revo Uninstaller" = Revo Uninstaller 1.95
"RGSS-RTP Standard_is1" = RGSS-RTP Standard
"RPGVX_J_is1" = RPGツクールVX
"RPGVXAce_RTP_is1" = RPGツクールVX Ace RTP
"RPGツクールVX RTP_is1" = RPGツクールVX RTP
"WinLiveSuite" = Windows Live Essentials

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-3922431837-200563891-1274897566-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2015/09/04 6:29:30 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0x2c0 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc9557b005 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: 580b503e-de1e-48ed-ba79-edef117e9962 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:30 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0xbb0 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc957d8555 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: 822b5e08-224e-439f-ad83-c2b1a34183c7 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:31 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0x3f8 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc959fc2a8 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: 54eaa168-b51d-4618-9066-990d266b6917 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:30 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

Error - 2015/09/04 6:29:30 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

Error - 2015/09/04 6:29:31 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

Error - 2015/09/04 6:29:32 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0x690 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc963243d8 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: 768fbd5d-d4e5-409f-8ee5-22c8db8c0d0e 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:32 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0x96c 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc969314f7 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: c2a43d65-bdb1-4b51-a48a-0c3b058145a1 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:32 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

Error - 2015/09/04 6:29:32 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

[ System Events ]
Error - 2015/09/04 6:30:29 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:30:29 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:30:29 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:30:29 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:30:31 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:32:03 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:32:09 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:32:52 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:33:30 | Computer Name = 【ユーザー名】-PC | Source = Service Control Manager | ID = 7001
Description = Net.Tcp Listener Adapter サービスは、次のエラーが原因で開始できなかった Net.Tcp Port Sharing
Service サービスに依存しています: %%1058

Error - 2015/09/04 6:33:58 | Computer Name = 【ユーザー名】-PC | Source = BTHUSB | ID = 327697
Description = ローカルの Bluetooth アダプターは不明なエラーが発生したため、使用されません。ドライバーはアンロードされました。


< End of report >
  • ぐぬぬ
  • 2015/09/04 (Fri) 21:17:35
ログ解析まで少々お待ちを
現在別の方の遠隔操作による駆除サポートを行っております。
その影響でログを読むのにお時間がかかっておりますので、
お手数ですがログチェック完了まで今しばらくお待ちください。
  • IVNO
  • MAIL
  • 2015/09/04 (Fri) 21:28:36
OTLで処置を
お待たせしました。

メモ帳を起動させ、以下をコピペしてください。
なお、:OTL、:Files、:Commands等はOTLでの処理方法を決める命令文です。
削除なされないようご注意ください。

------コピペこの下より------
:OTL
IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGNI_jaJP491
O2:[b]64bit:[/b] - BHO: (i-フィルター 5.0 ブラウザヘルパー) - {0FAF6F52-1AD4-4282-9EA1-3EC884DA7AA3} - C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar64.dll File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{857478e4-9b24-42e0-a39e-a800a9c0b3d5}: DhcpNameServer = 172.16.1.21 172.16.1.42
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
[2015/09/03 21:38:12 | 000,000,000 | ---D | C] -- %userprofile%\AppData\Roaming\Malwarebytes
[2015/09/03 21:37:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015/09/04 19:20:10 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job

:Files

:Commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペこの上まで------

コピペが完了しましたら、分かりやすいお名前をつけて保存してください。
その後、PCをセーフモードで起動させてください。
再度OTLを起動させ、Custom Scan/Fixesの項目内に上記で保存した内容をコピペしてください。
今回は駆除作業のため、その他のチェック項目はありません。
赤い文字の[Run Fix]をクリックして処置を開始してください。
OTLの処置に従って進めてゆき、通常モードで再起動を行う前後いずれかに処置ログが表示されますので、
そちらのログを貼り付けてご連絡ください。
またその際に状況報告もお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/04 (Fri) 21:53:23
Re: DNSUnlockerの広告等々・・・
状況報告とは、現状のIEなどの状況でよろしかったでしょうか?
まだ完全に状況を把握しているわけではありませんが、
おかげさまで勝手に迷惑なページに飛ばされることは少なくなったように思えます。
youtubeでいつも飛ばされていた動画も無事に再生できました。
しかし、たまに最初に報告していたようにwebページでリンク先へ移動しようとすると「Reimage Repair」に飛ばされてしまうので
完全に駆除できたわけではなさそうです。

以下ログです。

All processes killed
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-3922431837-200563891-1274897566-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{857478e4-9b24-42e0-a39e-a800a9c0b3d5}\\DhcpNameServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A69D345-D564-463c-AFF1-A69D9E530F96}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A69D345-D564-463c-AFF1-A69D9E530F96}\ not found.
Folder %userprofile%\AppData\RoamingMalwarebytes\ not found.
Folder C:\ProgramDataMalwarebytes\ not found.
File C:WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job not found.
File rity] not found.
File sethosts] not found.
File ptyflash] not found.
File ptyjava] not found.
File ptytemp] not found.
File eaterestorepoint] not found.
File boot] not found.

OTL by OldTimer - Version 3.2.69.0 log created on 09042015_222625

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ぐぬぬ
  • 2015/09/04 (Fri) 22:50:35
Re: DNSUnlockerの広告等々・・・
連続ですみません。
上で記載したwebページでリンク先へ移動しようとするとReimage Repair」に飛ばされる件ですが、
どうやらリンクにカーソルを合わせると突然小さなポップアップが出て、その状態でクリックすると飛ばされてしまうようです。
ポップアップの右下には「ad by DNSUnlocker」の文字がありました。
  • ぐぬぬ
  • 2015/09/04 (Fri) 22:54:40
ここで各ログを再確認します
こんばんは。
見るからに怪しいIDの悪代官です。
でも日本語はもっと怪しいので安心してください(←国に帰れ

IVNOさんがご多忙なので今度は自分がレスします。

OTLでの処置はだいぶできたようですが、

>たまに最初に報告していたようにwebページでリンク先へ移動しようとすると「Reimage Repair」に飛ばされてしまうので
>完全に駆除できたわけではなさそうです。

とのことで、まだ完治はしてませんね。

それでは一度全体の状態を見直しましょう。
お手数ですが再度CCで各タブのログとインストール情報とHJTログを取り直して、それらを見せてください。
それをまた調べてから次の対処を指示します。

なお、自分が次にレスできるのは明日夜以降になりそうなので、すみませんがご了承ください。
その前にでもIVNOさんから指示あればそちらに従ってもらえばいいです
  • 悪代官
  • 2015/09/04 (Fri) 23:40:21
Re: DNSUnlockerの広告等々・・・
悪代官さん、返信ありがとうございます。
以下ログとインストール情報です。

CC Windows

有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run OneDrive Microsoft Corporation "C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
有効 HKCU:Run swg Google Inc. "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
無効 HKLM:Run Adobe Reader Speed Launcher "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
無効 HKLM:Run ASUS Screen Saver Protector ASUS C:\Windows\AsScrPro.exe
有効 HKLM:Run ASUSPRP ASUSTek Computer Inc. "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
有効 HKLM:Run ASUSWebStorage ecareme C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
有効 HKLM:Run AthBtTray Atheros Commnucations "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
有効 HKLM:Run AtherosBtStack "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
有効 HKLM:Run ATKMEDIA ASUS C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
有効 HKLM:Run ATKOSD2 ASUS C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
有効 HKLM:Run BCSSync Microsoft Corporation "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
無効 HKLM:Run CLMLServer CyberLink "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
有効 HKLM:Run ETDCtrl %ProgramFiles%\Elantech\ETDCtrl.exe
有効 HKLM:Run HControlUser ASUS C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
有効 HKLM:Run HotKeysCmds Intel Corporation "C:\WINDOWS\system32\hkcmd.exe"
有効 HKLM:Run IgfxTray Intel Corporation "C:\WINDOWS\system32\igfxtray.exe"
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run IntelTBRunOnce Microsoft Corporation wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
有効 HKLM:Run Persistence Intel Corporation "C:\WINDOWS\system32\igfxpers.exe"
有効 HKLM:Run RtHDVBg Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
無効 HKLM:Run RtHDVCpl Realtek Semiconductor C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
有効 HKLM:Run SonicMasterTray Virage Logic Corporation / Sonic Focus C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
有効 HKLM:Run Wireless Console 3 ASUS C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
--------------------------------------------------------------------------------------------------------
CC IE

有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension Send by Bluetooth to Atheros Commnucations C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
無効 Helper CIESpeechBHO Class Atheros Commnucations C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
有効 Helper Google Toolbar Helper Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
有効 Helper Google Toolbar Helper Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
無効 Helper Groove GFS Browser Helper Microsoft Corporation C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
無効 Helper Groove GFS Browser Helper Microsoft Corporation C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
無効 Helper i-フィルター 5.0 ブラウザヘルパー C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar64.dll
無効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
無効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
有効 Toolbar Google Toolbar Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
有効 Toolbar Google Toolbar Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
--------------------------------------------------------------------------------------------------------
CC GoogleChrome

有効 App Gmail 8.1 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0
有効 App Google Search 0.0.0.30 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0
有効 App Google ドライブ 14.0 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.0_0
有効 App YouTube 4.2.7 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0
有効 Extension Google スプレッドシート 1.1 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0
有効 Extension Google スライド 0.9 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0
有効 Extension Google ドキュメント 0.9 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0
--------------------------------------------------------------------------------------------------------
スケジュールされたタスク
有効 Task ACMON ASUS C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task ASUS Live Update ASUSTeK Computer Inc. C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
有効 Task ASUS P4G ASUS C:\Program Files\P4G\BatteryLife.exe
有効 Task ASUS Secure Delete C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
有効 Task ASUS SmartLogon Console Sensor ASUS C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
有効 Task ATKOSD2 ASUS C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task DNSATLANTIC C:\Program Files (x86)\DNS Unlocker\dnsatlantic.exe /Scheduled
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task SidebarExecute C:\Program Files\Windows Sidebar\sidebar.exe /addGadget
有効 Task USBChargerPlus ASUSTek Computer Inc. C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
有効 Task {FD25F9F0-DFC4-41AD-8F12-59A0BD6C9E0E} Microsoft Corporation C:\Windows\system32\pcalua.exe -a C:\Users\【ユーザー名】\Desktop\アクアリウムス1.80\Game.exe -d C:\Users\【ユーザー名】\Desktop\アクアリウムス1.80
--------------------------------------------------------------------------------------------------------
インストール情報

Adobe Acrobat Reader DC - Japanese Adobe Systems Incorporated 2015/09/02 206 MB 15.008.20082
Adobe AIR Adobe Systems Incorporated 2015/08/28 4.0.0.1390
Adobe Flash Player 10 Plugin Adobe Systems Incorporated 2015/08/28 10.0.32.18
Asmedia ASM104x USB 3.0 Host Controller Driver Asmedia Technology 2012/04/17 2.27 MB 1.12.5.0
ASUS AI Recovery ASUS 2012/10/13 11.5 MB 1.0.27
ASUS LifeFrame3 ASUS 2012/04/17 30.2 MB 3.0.22
ASUS Live Update ASUS 2012/04/17 3.97 MB 3.0.6
ASUS Power4Gear Hybrid ASUS 2012/04/17 13.2 MB 1.1.45
ASUS Secure Delete ASUS 2012/04/17 6.35 MB 1.00.0007
ASUS SmartLogon ASUS 2012/04/17 11.1 MB 1.0.0011
ASUS Splendid Video Enhancement Technology ASUS 2012/04/17 19.2 MB 1.02.0033
ASUS USB Charger Plus AsusTek Computer Inc. 2012/04/17 2.0.2
ASUS Virtual Camera asus 2012/04/17 3.13 MB 1.0.21
ASUS WebStorage eCareme Technologies, Inc. 2015/08/28 3.0.108.222
AsusScr_U_24_Series_ENG ASUS 2015/08/28 159 MB 1.0.0001
Atheros Client Installation Program Atheros 2012/04/17 7.0
ATK Package ASUS 2012/04/17 12.0 MB 1.0.0013
Bluetooth Win7 Suite (64) Atheros Communications 2012/04/17 59.4 MB 7.02.000.55
CCleaner Piriform 2015/09/01 5.09
CyberLink LabelPrint CyberLink Corp. 2012/04/17 49.8 MB 2.5.3624
CyberLink Media Suite CyberLink Corp. 2012/04/17 40.4 MB 8.0.2926
CyberLink Power2Go CyberLink Corp. 2012/04/17 223 MB 7.0.0.1126
Dotfuscator Software Services - Community Edition PreEmptive Solutions 2013/03/29 6.45 MB 5.0.2500.0
Dotfuscator Software Services - Community Edition - JPN PreEmptive Solutions 2012/05/30 3.07 MB 5.0.2300.0
ETDWare PS/2-X64 8.0.5.3_WHQL ELAN Microelectronic Corp. 2015/08/28 8.0.5.3
Fast Boot ASUS 2012/04/17 1.46 MB 1.0.10
Google Chrome Google Inc. 2012/03/02 45.0.2454.85
Google Toolbar for Internet Explorer Google Inc. 2015/08/28 7.5.6710.2136
InstantOn for NB ASUS 2012/04/17 4.27 MB 2.1.3
Intel Driver Update Utility Intel 2015/08/28 19.6 MB 2.2.0.2
Intel(R) Control Center Intel Corporation 2012/04/17 1.2.1.1007
Intel(R) Management Engine Components Intel Corporation 2012/04/18 7.0.0.1144
Intel(R) Processor Graphics Intel Corporation 2013/03/29 9.17.10.2932
Java 8 Update 60 Oracle Corporation 2015/08/28 20.6 MB 8.0.600.27
Lhaz ちとらソフト 2015/08/28 2.2.4
MetasequoiaLE R3.0 2015/08/28
Microsoft .NET Framework 4 Multi-Targeting Pack Microsoft Corporation 2012/05/30 83.4 MB 4.0.30319
Microsoft ASP.NET MVC 2 Microsoft Corporation 2014/10/16 482 KB 2.0.60926.0
Microsoft ASP.NET MVC 2 - JPN Microsoft Corporation 2012/05/30 25.0 KB 2.0.50331.0
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools Microsoft Corporation 2012/05/30 2.25 MB 2.0.50217.0
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - JPN Microsoft Corporation 2012/05/30 2.13 MB 2.0.50402.0
Microsoft DirectX 9.0 SDK Update (October 2004) Microsoft® Corporation 2012/05/30 337 MB 9.02.3900
Microsoft Help Viewer 1.1 Microsoft Corporation 2015/08/28 3.97 MB 1.1.40219
Microsoft Help Viewer 1.1 Language Pack - JPN Microsoft Corporation 2015/08/28 1.95 MB 1.1.40219
Microsoft Office Professional Plus 2010 Microsoft Corporation 2015/08/28 14.0.7015.1000
Microsoft Silverlight Microsoft Corporation 2015/08/13 348 MB 5.1.40728.0
Microsoft Silverlight 3 SDK - 日本語 Microsoft Corporation 2012/05/30 33.3 MB 3.0.40818.0
Microsoft Silverlight 4 SDK - 日本語 Microsoft Corporation 2013/03/29 53.1 MB 4.0.50826.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2012/03/02 1.69 MB 3.1.0000
Microsoft SQL Server 2008 (64-bit) Microsoft Corporation 2015/08/28
Microsoft SQL Server 2008 Browser Microsoft Corporation 2013/03/29 7.97 MB 10.3.5500.0
Microsoft SQL Server 2008 Native Client Microsoft Corporation 2013/03/29 7.07 MB 10.3.5500.0
Microsoft SQL Server 2008 R2 Transact-SQL 言語サービス Microsoft Corporation 2013/03/29 6.79 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 データ層アプリケーション フレームワーク Microsoft Corporation 2013/03/29 5.61 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 データ層アプリケーション プロジェクト Microsoft Corporation 2013/03/29 14.1 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 管理オブジェクト Microsoft Corporation 2013/03/29 14.4 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 管理オブジェクト (x64) Microsoft Corporation 2013/03/29 6.59 MB 10.50.1750.9
Microsoft SQL Server 2008 Setup Support Files Microsoft Corporation 2015/07/16 54.2 MB 10.3.5538.0
Microsoft SQL Server Compact 3.5 SP2 JPN Microsoft Corporation 2012/05/30 3.66 MB 3.5.8080.0
Microsoft SQL Server Compact 3.5 SP2 x64 JPN Microsoft Corporation 2012/05/30 4.78 MB 3.5.8080.0
Microsoft SQL Server Database Publishing Wizard 1.4 Microsoft Corporation 2012/05/30 10.1 MB 10.1.2512.8
Microsoft SQL Server System CLR Types Microsoft Corporation 2013/03/29 991 KB 10.50.1750.9
Microsoft SQL Server System CLR Types (x64) Microsoft Corporation 2013/03/29 870 KB 10.50.1750.9
Microsoft SQL Server VSS Writer Microsoft Corporation 2013/03/29 4.02 MB 10.3.5500.0
Microsoft Sync Framework Runtime v1.0 SP1 (x64) ja Microsoft Corporation 2012/05/30 1.06 MB 1.0.3010.0
Microsoft Sync Framework SDK v1.0 SP1 ja Microsoft Corporation 2012/05/30 30.1 MB 1.0.3010.0
Microsoft Sync Framework Services v1.0 SP1 (x64) ja Microsoft Corporation 2012/05/30 2.92 MB 1.0.3010.0
Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) ja Microsoft Corporation 2012/05/30 630 KB 2.0.3010.0
Microsoft Team Foundation Server 2010 オブジェクト モデル - 日本語 Microsoft Corporation 2015/08/28 10.0.40219
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2012/06/04 300 KB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/05/28 230 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2012/04/17 596 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 Microsoft Corporation 2012/05/30 599 KB 9.0.30729.4974
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2012/06/04 600 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319 Microsoft Corporation 2012/05/30 314 KB 10.0.30319
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/16 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 Microsoft Corporation 2013/03/29 20.5 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/16 11.1 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 Microsoft Corporation 2013/03/29 15.9 MB 10.0.40219
Microsoft Visual F# 2.0 Runtime Microsoft Corporation 2013/03/29 5.84 MB 10.0.40219
Microsoft Visual F# 2.0 Runtime Language Pack - 日本語 Microsoft Corporation 2012/05/30 1.34 MB 10.0.30319
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools Microsoft Corporation 2013/03/29 35.4 MB 10.0.40219
Microsoft Visual Studio 2010 Professional - 日本語 Microsoft Corporation 2015/08/28 10.0.30319
Microsoft Visual Studio 2010 Service Pack 1 Microsoft Corporation 2015/08/28 75.9 MB 10.0.40219
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Corporation 2015/08/28 10.0.50903
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語 Microsoft Corporation 2015/08/28 10.0.50903
Microsoft Visual Studio Macro Tools Microsoft Corporation 2015/08/28 9.0.30729
Microsoft Visual Studio Macro Tools - JPN Language Pack Microsoft Corporation 2015/08/28 9.0.30729
PowerWiz ASUS 2012/04/17 6.89 MB 1.0.3
Prominence 2015/08/28
Realtek Ethernet Controller Driver Realtek 2012/04/17 7.44.421.2011
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2015/08/28 6.0.1.7535
Realtek USB 2.0 Reader Driver Realtek Semiconductor Corp. 2012/04/17 6.1.7600.10008
Revo Uninstaller 1.95 VS Revo Group 2015/08/28 1.95
RGSS-RTP Standard Enterbrain 2013/04/27 1.03
RPGツクール2000 ランタイムパッケージ 2015/08/28
RPGツクールVX Enterbrain 2013/11/12 140 MB 1.03a
RPGツクールVX Ace RTP Enterbrain 2013/11/10 194 MB 1.00
RPGツクールVX RTP Enterbrain 2013/11/12 42.1 MB 1.02
RPGツクール2003 ランタイムパッケージ 2015/08/28
SceneSwitch ASUS 2012/04/17 2.22 MB 1.0.8
SlimDX Redistributable for .NET 2.0 (September 2011) SlimDX Group 2014/04/12 15.5 MB 2.0.12.43
SlimDX Runtime .NET 2.0 (January 2012) SlimDX Group 2014/04/12 17.2 MB 2.0.13.43
Sonic Focus Synopsys 2012/04/17 4.31 MB 1.0.0.4
Synaptics Pointing Device Driver Synaptics Incorporated 2015/08/28 46.4 MB 19.0.9.5
Unity Web Player Unity Technologies ApS 2015/08/28 12.0 MB
Visual Studio 2010 Prerequisites - English Microsoft Corporation 2013/03/29 23.2 MB 10.0.40219
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 JPN Microsoft Corporation 2012/05/30 11.2 MB 4.0.8080.0
WCF RIA Services V1.0 SP1 Microsoft Corporation 2013/03/29 12.3 MB 4.1.60114.0
Web Deployment Tool Microsoft Corporation 2012/05/30 3.10 MB 1.1.0618
Windows Live Essentials Microsoft Corporation 2012/03/02 15.4.3538.0513
WinFlash ASUS 2012/04/17 856 KB 2.31.1
Wireless Console 3 ASUS 2012/04/17 9.05 MB 3.0.21
インテル(R) ターボ・ブースト・テクノロジー・モニター 2.0 インテル 2012/04/17 13.2 MB 2.1.23.0
リモート接続用の Windows Live Mesh ActiveX コントロール (日本語) Microsoft Corporation 2012/03/02 5.57 MB 15.4.5722.2
--------------------------------------------------------------------------------------------------------
HJT ログ

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 0:21:26, on 2015/09/05
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Users\【ユーザー名】\Downloads\HijackThis.exe

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: Tor Win32 Service (tor) - Unknown owner - C:\Program Files (x86)\Tor\tor.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10724 bytes

  • ぐぬぬ
  • 2015/09/05 (Sat) 00:35:21
申し訳ありませんが…
IVNOさんの 2015/09/04 (Fri) 01:30:30
の投稿から
私の 2015/09/04 (Fri) 21:11:21
までの3つのログに名前の一部が入ってしまっているので削除をお願いしたいです。
重ね重ね申し訳ございません。
  • ぐぬぬ
  • 2015/09/05 (Sat) 00:42:58
処置しました
残念ながら別館は私が管理人ですので、
投稿の削除や編集は私しかできません。
その私はちょっと多忙でなかなか時間がなかったため、
レスの削除まで手が回っていませんでした。
できることなら今すぐリカバリし、
PCのお名前を本名とは無縁のものにするのが
今後のためではあるのですが・・・
  • IVNO
  • MAIL
  • 2015/09/05 (Sat) 00:51:37
Re: DNSUnlockerの広告等々・・・
IVNOさん、対応していただきありがとうございます。
リカバリですか…
リカバリは今までの制作物や様々なデータが消えてしまうわけですよね?
やはり、それはまだやめておこうと思います。
幸いユーザー名もニックネームのようなもので、ある程度よく使われている部分でしたし(【ユーザー名】助とか)
いずれ今使っているパソコンを買い替える時までは勉強代と思っておきます。
  • ぐぬぬ
  • 2015/09/05 (Sat) 18:08:41
少しCCで処置を
ログを確認したところ、CCで一部処置すべき項目がありますので、
そちらだけ処理しましょう。

CCを起動させ、ツール→スタートアップの各項目を開き、
該当するものを無効→エントリの削除の順番でクリックしてください。

Internet Explorer
無効 Helper i-フィルター 5.0 ブラウザヘルパー C:\Program Files (x86)\Digital Arts\IFP5\app\bin\ifp5toolbar64.dll

スケジュールされたタスク
有効 Task {FD25F9F0-DFC4-41AD-8F12-59A0BD6C9E0E} Microsoft Corporation C:\Windows\system32\pcalua.exe -a C:\Users\【ユーザー名】\Desktop\アクアリウムス1.80\Game.exe -d C:\Users\【ユーザー名】\Desktop\アクアリウムス1.80

無効にできないもの、既に無効になっているものはそのままエントリの削除を、
エントリが存在しない場合は放置で結構です。
これが終わったら今一度CCのスタートアップの書くログをお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/05 (Sat) 21:35:55
Re: DNSUnlockerの広告等々・・・
返答が遅れてしまい申し訳ありません。

無事作業終了いたしました。
以下ログです。

windows-----------------------------------------------------------------------------------------------

有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run OneDrive Microsoft Corporation "C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
有効 HKCU:Run swg Google Inc. "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
無効 HKLM:Run Adobe Reader Speed Launcher "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
無効 HKLM:Run ASUS Screen Saver Protector ASUS C:\Windows\AsScrPro.exe
有効 HKLM:Run ASUSPRP ASUSTek Computer Inc. "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
有効 HKLM:Run ASUSWebStorage ecareme C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
有効 HKLM:Run AthBtTray Atheros Commnucations "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
有効 HKLM:Run AtherosBtStack "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
有効 HKLM:Run ATKMEDIA ASUS C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
有効 HKLM:Run ATKOSD2 ASUS C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
有効 HKLM:Run BCSSync Microsoft Corporation "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
無効 HKLM:Run CLMLServer CyberLink "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
有効 HKLM:Run ETDCtrl %ProgramFiles%\Elantech\ETDCtrl.exe
有効 HKLM:Run HControlUser ASUS C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
有効 HKLM:Run HotKeysCmds Intel Corporation "C:\WINDOWS\system32\hkcmd.exe"
有効 HKLM:Run IgfxTray Intel Corporation "C:\WINDOWS\system32\igfxtray.exe"
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run IntelTBRunOnce Microsoft Corporation wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
有効 HKLM:Run Persistence Intel Corporation "C:\WINDOWS\system32\igfxpers.exe"
有効 HKLM:Run RtHDVBg Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
無効 HKLM:Run RtHDVCpl Realtek Semiconductor C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
有効 HKLM:Run SonicMasterTray Virage Logic Corporation / Sonic Focus C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
有効 HKLM:Run Wireless Console 3 ASUS C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

IE-----------------------------------------------------------------------------------------------

有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension Send by Bluetooth to Atheros Commnucations C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
無効 Helper CIESpeechBHO Class Atheros Commnucations C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
有効 Helper Google Toolbar Helper Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
有効 Helper Google Toolbar Helper Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
無効 Helper Groove GFS Browser Helper Microsoft Corporation C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
無効 Helper Groove GFS Browser Helper Microsoft Corporation C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
無効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
無効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
有効 Toolbar Google Toolbar Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
有効 Toolbar Google Toolbar Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

google chrome-----------------------------------------------------------------------------------------------

有効 App Gmail 8.1 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0
有効 App Google Search 0.0.0.30 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0
有効 App Google ドライブ 14.0 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.0_0
有効 App YouTube 4.2.7 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0
有効 Extension Google スプレッドシート 1.1 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0
有効 Extension Google スライド 0.9 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0
有効 Extension Google ドキュメント 0.9 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0

スケジュールされたタスク-----------------------------------------------------------------------------------------------

有効 Task ACMON ASUS C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task ASUS Live Update ASUSTeK Computer Inc. C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
有効 Task ASUS P4G ASUS C:\Program Files\P4G\BatteryLife.exe
有効 Task ASUS Secure Delete C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
有効 Task ASUS SmartLogon Console Sensor ASUS C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
有効 Task ATKOSD2 ASUS C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task DNSATLANTIC C:\Program Files (x86)\DNS Unlocker\dnsatlantic.exe /Scheduled
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task SidebarExecute C:\Program Files\Windows Sidebar\sidebar.exe /addGadget
有効 Task USBChargerPlus ASUSTek Computer Inc. C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe

  • ぐぬぬ
  • 2015/09/05 (Sat) 22:56:35
HPでスキャンを
CCのログの再チェックを行いましたが、こちらはよさそうです。

以下のソフトウェアをご用意ください。

HerdProtect(通称:HP)
http://www.herdprotect.com/downloads.aspx
インストール版でもポータブル版でも構いません。
インストール版の場合、アンインストールの際は、セーフモードでGeekを利用してアンインストールされてください。
また、トレンドマイクロのウイルスバスターとの相性が悪いとの報告も受けております。
相性の問題でスキャンが正常にできないときは、その旨をご報告ください。
さらに、本ソフトウェアにより検出されたものすべてがマルウェアと言うわけではありません。
HPは駆除機能もありますが、誤検出率8割以上を誇る諸刃の剣ですので、駆除はOTLを用います。

準備ができましたら、まずゲームのインストーラーなど、極端に重たいファイルがある場合は、
そちらの不要ファイルを事前にPC内から手動削除し、ごみ箱からも消しておいてください。
これらをHPが不審プログラムとして拾うと、1日や2日は平気でスキャンにかかってしまいます。
PCが通常モードで起動していることを確認し、HerdProtectを起動させます。
ソフトウェアの特性として、ファイルのスキャンにインターネット回線を利用します。
インターネット回線がご利用できないセーフモード時では正常に動作しませんので、
セーフモードで起動中の場合は通常モードに切り替えてください。
Scanボタンがありますので、こちらを押してスキャンを行ってください。
スキャンに必要な情報を収集したり、発見された不審なソフトウェアを
各種セキュリティソフトで調査している間は、スキャン作業が停止します。
スキャンが進行しないからと言ってフリーズしたわけではありませんので、
スキャンが完了するまで今しばらくお待ちください。
スキャンが完了しましたらスキャン結果が表示されますので、
画面右上にあるSave resultsという文字をクリックしてログを出力してください。
出力されたログを貼り付けてご連絡をお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/06 (Sun) 07:49:35
Re: DNSUnlockerの広告等々・・・
スキャンが終わりました。
ポータブル版はアンインストールする際はどうすればよいのでしょうか?

以下ログです。

Saved date: 2015/09/06 13:26:52
Files detected: 208
Files scanned: 10,478
Processes scanned: 78
Modules scanned: 832
ASEPs scanned: 563
Downloads scanned: 2
Deep analysis: 40/29
---------------------------------------------------------------------------------

Files

---------------------------------------------------------------------------------

File path: c:\program files (x86)\tor\tor.exe
Publisher:
MD5: 506b0b498216371d64abb69145b70e4c
SHA-1: 71da7037f29bf8afe78d2a504350cdaf7cc6c9da
Created: 2013/08/26 19:27:44
Detections: 2
Determination: Ignore detections (false positive)
- ViRobot as Trojan.Win32.S.Agent.3233806 (Undefined)
- Rising Antivirus as PE:Malware.XPACK/RDM!5.1

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\downloads\apcsetuprmrt.exe
Publisher: Advancedpccare.com
Signer: PCVARK SOFTWARE PRIVATE LIMITED
MD5: 3f3723a0ae02a466b2c7fba8b4d8d9ee
SHA-1: b160187883e81aa81d2705143ba047d18aa3cbee
Created: 2015/08/24 17:05:37
Detections: 1
Determination: Inconclusive
- Reason Heuristics as PUP.PCCare.Optional.Installer.Meta (L) (Adware)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\downloads\adwcleaner.exe
Publisher:
MD5: 2f4e1e2f3630243c76be815fddcbbfa8
SHA-1: 4a4ea19c72bbea0ccaa7e0e1eca62a7ec687c2ec
Created: 2015/09/03 20:05:38
Detections: 1
Determination: Ignore detections (false positive)
- Qihoo 360 Security as HEUR/QVM11.1.Malware.Gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\downloads\hijackthis.exe
Publisher: Trend Micro Inc.
MD5: 47811d50390a86a17102d7496e6eabb9
SHA-1: 2623749cdb27887f6746acdee7e8065475f8b541
Created: 2015/09/01 23:40:14
Detections: 2
Determination: Ignore detections (false positive)
- Kingsoft AntiVirus as Win32.HeurC.KVM099.a.(kcloud) (Undefined)
- Rising Antivirus as PE:Trojan.VBInject!1.6546 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\downloads\otl.exe
Publisher: OldTimer Tools
MD5: 4adcfee16ee9978f06157634669d36fb
SHA-1: 30b37076552e49276836d02dd73d038c27dbbee9
Created: 2015/09/04 20:05:17
Detections: 2
Determination: Ignore detections (false positive)
- Agnitum Outpost as Packed/PECompact
- Bkav FE as HW32.CDB (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\rpg素材\ひきも記素材\プロジェクト形式\hikimoki_rgss3\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2013/12/28 0:40:52
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\rpg素材\ひきも記素材\プロジェクト形式\itanlaby\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2013/12/28 0:40:55
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\rpg素材\ひきも記素材\プロジェクト形式\rgss3_stg\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2013/12/28 0:41:19
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\bbrider\b.b.ライダー\rpg_rt.exe
Publisher:
MD5: b540045afe1b0b111ba966793f316bcc
SHA-1: 71e67bd8ba7ad143bfb9abd60b43f92d99278aab
Created: 2014/04/16 23:46:07
Detections: 10
Determination: UndefinedMalware
- nProtect as Backdoor/W32.Hupigon.950784.C (Undefined)
- F-Prot as W32/Backdoor2.GPHI (Undefined)
- Norman as Hupigon.ESZN (Undefined)
- Total Defense as Win32/Pigeon.BCYR (Undefined)
- NANO AntiVirus as Trojan.Win32.GPHJ.cozfa (Undefined)
- VIPRE Antivirus as Trojan.Win32.Generic (Undefined)
- Commtouch SDK as W32/Backdoor.LKHM-3834 (Undefined)
- Vba32 AntiVirus as Backdoor.Hupigon (Undefined)
- Panda Antivirus as Trj/Downloader.MDW (Undefined)
- Rising Antivirus as PE:Trojan.Win32.Generic.12A2F0C9!312668361 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\inn_sub\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2014/03/12 23:47:25
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\janken\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2014/01/12 19:54:06
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\rpg_loader_\data\caldix\caldix.exe
Publisher:
MD5: 0f1a6ea206019a430b7b198f18802b68
SHA-1: c15783684574baf3f0efa8c108ee49c771b6322e
Created: 2013/07/07 1:42:53
Detections: 2
Determination: Ignore detections (false positive)
- The Hacker as Posible_Worm32 (Undefined)
- Vba32 AntiVirus as BScope.Malware-Cryptor.Slota (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\rpg_loader_\data\runtime\2000_110\drpg_rt.exe
Publisher:
MD5: f18d30280bb65afa260cc13b5fec68dd
SHA-1: fc1e3feeb32f41850ead4a146658edf26f73c80e
Created: 2013/07/07 1:43:41
Detections: 2
Determination: Ignore detections (false positive)
- Trend Micro House Call as Suspicious_GEN.F47V0323 (Undefined)
- ByteHero BDV as Trojan-Downloader.Win32.DlfBfkg.ln (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\rpg_loader_\data\runtime\2003_109\drpg_rt.exe
Publisher:
MD5: 289017ea31a2d77d89e199e19aba651e
SHA-1: b140c0576f56e4ec27ab3765e9c5c89a9a65cdd5
Created: 2013/07/07 1:43:42
Detections: 21
Determination: UndefinedMalware
- Bkav FE as W32.Clod92b.Trojan (Undefined)
- MicroWorld eScan as Backdoor.Hupigon.155927 (Undefined)
- nProtect as Backdoor/W32.Hupigon.950784.C (Undefined)
- NANO AntiVirus as Trojan.Win32.GPHJ.cozfa (Undefined)
- Norman as Hupigon.IXFQ (Undefined)
- Total Defense as Win32/Pigeon.BCYR (Undefined)
- Trend Micro House Call as TROJ_SPNR.04JO11 (Undefined)
- Bitdefender as Backdoor.Hupigon.155927 (Undefined)
- Lavasoft Ad-Aware as Backdoor.Hupigon.155927 (Undefined)
- Sophos as Mal/Generic-S (Undefined)
- Comodo Security as UnclassifiedMalware (Undefined)
- F-Secure as Backdoor.Hupigon.155927 (Undefined)
- Trend Micro as TROJ_SPNR.04JO11 (Undefined)
- Emsisoft Anti-Malware as Backdoor.Hupigon.155927 (Undefined)
- G Data as Backdoor.Hupigon.155927 (Undefined)
- Vba32 AntiVirus as Backdoor.Hupigon (Undefined)
- Baidu Antivirus as Trojan.Win32.Agent.DYVCPUT (Undefined)
- IKARUS anti.virus as Backdoor.Hupigon (Undefined)
- AVG as BackDoor.Hupigon5 (Undefined)
- Panda Antivirus as Trj/CI.A (Undefined)
- Qihoo 360 Security as Win32/Backdoor.Hupigon.be0 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\rpg_loader_\data\runtime\2003_109\rpg_rt.exe
Publisher:
MD5: b540045afe1b0b111ba966793f316bcc
SHA-1: 71e67bd8ba7ad143bfb9abd60b43f92d99278aab
Created: 2013/07/07 1:43:41
Detections: 10
Determination: UndefinedMalware
- nProtect as Backdoor/W32.Hupigon.950784.C (Undefined)
- F-Prot as W32/Backdoor2.GPHI (Undefined)
- Norman as Hupigon.ESZN (Undefined)
- Total Defense as Win32/Pigeon.BCYR (Undefined)
- NANO AntiVirus as Trojan.Win32.GPHJ.cozfa (Undefined)
- VIPRE Antivirus as Trojan.Win32.Generic (Undefined)
- Commtouch SDK as W32/Backdoor.LKHM-3834 (Undefined)
- Vba32 AntiVirus as Backdoor.Hupigon (Undefined)
- Panda Antivirus as Trj/Downloader.MDW (Undefined)
- Rising Antivirus as PE:Trojan.Win32.Generic.12A2F0C9!312668361 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\ruina121\start.exe
Publisher:
MD5: 1511e1ae0a7db20759ab361404f2052e
SHA-1: 96946913b9665a16c1584485ebfe0f22700a1622
Created: 2014/03/20 16:59:02
Detections: 3
Determination: Inconclusive
- Sophos as Mal/EncPk-ACO (Undefined)
- SUPERAntiSpyware as Trojan.Agent/Gen-EncPk (Undefined)
- Rising Antivirus as PE:Malware.XPACK/RDM!5.1

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\ruina121\start_window.exe
Publisher:
MD5: f5280ccfacaa421ef4aa75730b31ff09
SHA-1: 4065b67a2f9105b7a85a917091c6093cd4da35bf
Created: 2014/03/20 16:59:02
Detections: 2
Determination: Inconclusive
- SUPERAntiSpyware as Trojan.Agent/Gen-EncPk (Undefined)
- Sophos as Mal/EncPk-ACO (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\sakyuyado1.1\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2013/12/29 10:50:12
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\shinigami\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2015/01/02 3:29:08
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\ts遏ュ邱ィ閼ア蜃コ\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2012/12/14 18:25:32
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\いせおんrpg\start.exe
Publisher:
MD5: 53f63df85749e04a550512584fb3cbad
SHA-1: b5a637585ff9b7cb00dcfe930f8953a0c602c5fe
Created: 2014/12/27 1:50:04
Detections: 1
Determination: Ignore detections (false positive)
- Trend Micro House Call as TROJ_GEN.R0C1H08LN14 (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\まどtasトライアル1.2\まどtasデモ\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2014/02/15 2:15:22
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\ゆゆゆrpgv1_0\game.exe
Publisher:
MD5: bd9ebb7d09f9111a9f0a0ba2238eaf80
SHA-1: 28c753124d845f61373be87d392ab839914ebdc5
Created: 2015/02/25 23:46:30
Detections: 1
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Trojan/Win32.KillAV.gen (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\よんよん氏詰め合わせ\bouei_102\boueigame_102.exe
Publisher:
MD5: 328b14adacad52d43cf0190399ab784f
SHA-1: a7b102b18213e0f704389b35fd7793c597557546
Created: 2013/09/29 11:55:11
Detections: 3
Determination: Inconclusive
- The Hacker as Trojan/Constructor.IDL.dj (Undefined)
- Emsisoft A-Squared as Constructor.Win32.IDL!IK (Undefined)
- IKARUS anti.virus as Constructor.Win32.IDL (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\よんよん氏詰め合わせ\こねた\game.exe
Publisher:
MD5: c22b8d8acb738776d94ea0cc10277144
SHA-1: 4dcc713487826be8c67f614d0f90b0ab59d2215c
Created: 2013/09/29 13:18:45
Detections: 3
Determination: Inconclusive
- Bkav FE as W32.Clod248.Trojan (Undefined)
- The Hacker as Backdoor/SdBot.ysj (Undefined)
- ViRobot as Trojan.Win32.A.ShipUp.69632.M (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\よんよん氏詰め合わせ\こねた\rgss103j.dll
Publisher:
MD5: db8c00286dc21dd0a92bfd96f8f9fd14
SHA-1: 73e5dccd08c988f18c8e7537cf71fab7b34ae9a8
Created: 2013/09/29 13:18:48
Detections: 2
Determination: Ignore detections (false positive)
- CMC Antivirus as Trojan.Win32.Monder.2!O (Undefined)
- Antiy Labs AVL as Trojan[:HEUR]/Win32.Unknown (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\シルエットノート\game.exe
Publisher:
MD5: c22b8d8acb738776d94ea0cc10277144
SHA-1: 4dcc713487826be8c67f614d0f90b0ab59d2215c
Created: 2014/12/23 1:06:42
Detections: 3
Determination: Inconclusive
- Bkav FE as W32.Clod248.Trojan (Undefined)
- The Hacker as Backdoor/SdBot.ysj (Undefined)
- ViRobot as Trojan.Win32.A.ShipUp.69632.M (Undefined)

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\シルエットノート\save\rgss100j.dll
Publisher:
MD5: 011e30eb8eadb7da710b7738b5bbe465
SHA-1: b242e204d8490a3346dd1169c4494b39f3b902ea
Created: 2014/12/23 1:06:39
Detections: 1
Determination: Ignore detections (false positive)
- McAfee Web Gateway as Heuristic.BehavesLike.Win32.Suspicious-BAY.G

---------------------------------------------------------------------------------

File path: c:\users\【ユーザー名】\desktop\ゲーム\シルエットノート\save\rgss103j.dll
Publisher:
MD5: db8c00286dc21dd0a92bfd96f8f9fd14
SHA-1: 73e5dccd08c988f18c8e7537cf71fab7b34ae9a8
Created: 2014/12/23 1:06:42
Detections: 2
Determination: Ignore detections (false positive)
- CMC Antivirus as Trojan.Win32.Monder.2!O (Undefined)
- Antiy Labs AVL as Trojan[:HEUR]/Win32.Unknown (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\syswow64\rgss100j.dll
Publisher:
MD5: 1be0af3325aead4305cb78670d93a96f
SHA-1: 62d76585bd1629c5adf67733a7a774260859f206
Created: 2013/04/27 17:04:43
Detections: 1
Determination: Ignore detections (false positive)
- CMC Antivirus as Trojan.Win32.Monder.2!O (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\syswow64\sfx32gui.dat
Publisher: heropa@dream.com
MD5: fbb68217acf049d29138415badb744a8
SHA-1: 7672651f93feecb30a639acca4f5aa9508134593
Created: 2013/07/07 1:43:28
Detections: 2
Determination: Ignore detections (false positive)
- The Hacker as Posible_Worm32 (Undefined)
- Zillya! Antivirus as Trojan.Obfuscated.Win32.69460 (Undefined)

---------------------------------------------------------------------------------

File path: c:\windows\syswow64\voiceactivationmanager.dll
Publisher: Microsoft Corporation
MD5: b5009272f86c94d193c67f89686a3708
SHA-1: 0f0ad29ea0c25a8bda919b4fd33a046a5fbde4e5
Created: 2015/08/28 18:17:53
Detections: 1
Determination: Ignore detections (false positive)
- AegisLab AV Signature as Troj.W32.Delf (Undefined)

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\10033\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\10076\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\10921\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\11193\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\11356\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\11456\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\11496\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\11515\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\11886\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\11996\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\12035\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\12505\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\12573\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\12676\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\13354\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\14369\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\14636\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\14695\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\15268\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\15548\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\15649\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\15740\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\15903\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\1633\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\16943\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\17204\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\18268\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\18739\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\19541\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\19588\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\20029\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\20170\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\20575\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\20750\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\21213\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\2229\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\22321\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\22518\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\22588\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\22643\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\22814\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\23108\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\23130\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\23381\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\23492\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\24014\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\24741\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\24992\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\25413\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\25483\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\27166\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\27420\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\27480\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\27707\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\28520\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\28806\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\29294\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\29332\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\30226\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\30892\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\31013\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\31525\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\31797\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\32067\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\32593\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\3267\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\3386\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\3388\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\362\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\3658\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\4025\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\4220\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\5617\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\645\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\7132\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\719\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\7835\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\7865\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\8134\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\8633\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\8925\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\908\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\9133\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\924\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\9267\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSyste
  • ぐぬぬ
  • 2015/09/06 (Sun) 13:32:27
現在117/208です
HPのログを確認いたしましたが、今ご提示いただいているのは全208個の検出のうち117個までですね。
残り91個のログをお待ちしております。
  • IVNO
  • MAIL
  • 2015/09/06 (Sun) 13:35:27
こちらを先に対応お願いします
すいません、先ほど提出したログに大量のフリーゲーム名が載ってしまっているので修正したいです。
改めて投稿するので先ほどのものを削除願います。
もしかしたら迷惑に思う作者さんがいるかもしれないので、お願いします。
  • ぐぬぬ
  • 2015/09/06 (Sun) 13:39:27
それは困ります
フリーゲームも感染源となっている可能性が大いにありますし、見る限りゲームに感染しています。
それを見極める必要があるため、ログの改変は行われないでください。
実際問題68個のセキュリティソフト中21個がマルウェア判定を出しています。
1個や2個のセキュリティソフトがマルウェア判定を出すなら誤検出とも言えますが、
この規模で検出されているとなるとどう考えても無感染であるとは言えないでしょう。
ログの改変を行うと適切なご案内ができなくなり、
結果として処置に影響が出る可能性が高くなります。
なお相談者さんの本名を伏せること以上のログの改変は、
悪代官の伏魔殿からの永久追放処置に直結していますのでご注意ください。
  • IVNO
  • MAIL
  • 2015/09/06 (Sun) 13:41:27
わかりました
申し訳ございません。
では、このログを使用する作業が終わった後にというのはお願いできますか?
  • ぐぬぬ
  • 2015/09/06 (Sun) 13:54:24
ログの続きです
すみません、コピペする際に範囲を間違えてしまっていたようです。
以下続きです。
File path: c:\programdata\adobe\arm\reader_10.0.0\9267\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\946\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\9659\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\adobe\arm\reader_10.0.0\9898\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\10033\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\10076\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\10921\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\11193\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\11356\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\11456\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\11496\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\11515\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\11886\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\11996\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\12035\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\12505\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\12573\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\12676\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\13354\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\14369\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\14636\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\14695\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\15268\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\15548\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\15649\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\15740\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\15903\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\1633\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\16943\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\17204\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\18268\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\18739\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\19541\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\19588\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\20029\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\20170\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\20575\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\20750\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\21213\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\2229\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\22321\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\22518\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\22588\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\22643\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\22814\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\23108\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\23130\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\23381\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\23492\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\24014\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\24741\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\24992\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\25413\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\25483\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\27166\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\27420\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\27480\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\27707\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\28520\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\28806\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\29294\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\29332\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\30226\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\30892\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\31013\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\31525\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\31797\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\32067\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\32593\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\3267\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\3386\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\3388\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\362\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\3658\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\4025\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\4220\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\5617\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\645\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\7132\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\719\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\7835\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\7865\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\8134\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\8633\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\8925\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\908\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\9133\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\924\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\9267\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\946\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\9659\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

---------------------------------------------------------------------------------

File path: c:\programdata\application data\adobe\arm\reader_10.0.0\9898\adobearm.exe
Publisher: Adobe Systems Incorporated
Signer: Adobe Systems, Incorporated
MD5: 48be298f7fd1bef4d8fbacb04d8d95c4
SHA-1: 84d9a67a700a87c8c5ddd6b7dfc5eef70fa98020
Created: 2013/04/05 6:06:36
Detections: 2
Determination: Ignore detections (false positive)
- Antiy Labs AVL as Backdoor/Win32.Swrort (Undefined)
- Boost by Reason as UnneededApp.Startup.AdobeSystemsorporated.I

  • ぐぬぬ
  • 2015/09/06 (Sun) 14:00:10
規約の確認をお願いいたします
規約の冒頭で私はこのように記述いたしております。

はじめに

悪代官の伏魔殿別館にお越しいただき、誠にありがとうございます。
悪代官の伏魔殿本館および別館は、コンピューターウイルスやアド(広告)ウェアなどの、
マルウェアの自力駆除をサポートしている、有志によるマルウェア駆除のための情報交換広場です。

言い換えると、奉仕作業として行うマルウェア駆除に関する知識とログ提供の場となります。

情報交換をするための場ですので、交換するのにふさわしい情報がなければなりません。
それらの情報は私たち回答者が提供するものばかりではなく、
相談者の皆さんとも情報を交換しつつ処置を行うわけですから、
意図的に情報を伏せて公開することは、悪代官の伏魔殿での対応としてふさわしくないのです。
これらのログを解析して自身の駆除に役立てている方もおられますが、
そのような方のためにもいかなるログも改変しないことが重要になるのです。
比較対象を意図的に隠蔽する行為はその方針に反する行為となります。
本来はもう少し分かりやすく規約を書いていたのですが、
長いため誰も読まずにお越しになられて、結果違反相談者さんを追放と言う流れになりました。
それから規約を端的にまとめて読みやすくした結果、細かな部分が記述できませんでした。
結局のところ暗に記述した部分が増えてしまったわけですが、ご理解いただければと思います。
  • IVNO
  • MAIL
  • 2015/09/06 (Sun) 14:08:34
わかりました
わかりました。
そういう事でしたら仕方ないですね。
  • ぐぬぬ
  • 2015/09/06 (Sun) 14:35:19
HPは削除しOTLで処置を
ログを確認したところ、ゲームに2件、それ以外に1件、ごみ1件でした。
HPは不要ですので、導入時の指示に従って削除なされてください。

メモ帳を起動させ、以下をコピペしてください。
なお、:OTL、:Files、:Commands等はOTLでの処理方法を決める命令文です。
削除なされないようご注意ください。

------コピペこの下より------
:Files
c:\program files (x86)\tor
%userprofile%\downloads\adwcleaner.exe
%userprofile%\desktop\ゲーム\bbrider
%userprofile%\desktop\ゲーム\rpg_loader_

:Commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペこの上まで------

コピペが完了しましたら、分かりやすいお名前をつけて保存してください。
その後、PCをセーフモードで起動させてください。
再度OTLを起動させ、Custom Scan/Fixesの項目内に上記で保存した内容をコピペしてください。
今回は駆除作業のため、その他のチェック項目はありません。
赤い文字の[Run Fix]をクリックして処置を開始してください。
OTLの処置に従って進めてゆき、通常モードで再起動を行う前後いずれかに処置ログが表示されますので、
そちらのログを貼り付けてご連絡ください。
またその際に状況報告もお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/06 (Sun) 14:57:08
Re: DNSUnlockerの広告等々・・・
返信が遅れてしまい申し訳ありません。

状況ですが動画は再生できますし、
まだ少ししか触っていないので不安はありますが、
IEやGoogleChromeで飛ばされることもなくなったように思えます。

しかし、MicrosoftEdgeのブラウザで、一部の文字が青くなり、カーソルを合わせるとDNS関連のポップアップが出ます。
ただ、このブラウザを使用している理由が今回の現象について情報をやり取りする際に
まだ操作しやすかった(飛ばされる頻度がやや少なかった)というだけなので最悪の場合アンインストールも問題なしです。

以下ログです。

All processes killed
========== FILES ==========
File\Folder c:program files (x86)\tor not found.
File/Folder C:\Users\【ユーザー名】downloads\adwcleaner.exe not found.
File/Folder C:\Users\【ユーザー名】desktop\ゲーム\bbrider not found.
File/Folder C:\Users\【ユーザー名】desktop\ゲーム\rpg_loader_ not found.
File\Folder :Commands not found.
File\Folder [purity] not found.
File\Folder [resethosts] not found.
File\Folder [emptyflash] not found.
File\Folder [emptyjava] not found.
File\Folder [emptytemp] not found.
File\Folder [createrestorepoint] not found.
File\Folder [reboot] not found.

OTL by OldTimer - Version 3.2.69.0 log created on 09062015_154010

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ぐぬぬ
  • 2015/09/06 (Sun) 17:28:13
やりましょうか大仕事
もうここまできたら私も本気を見せなければなりませんね。
OTLは再度使用しますので保管なされておいてください。

ログ総数が数百万文字になるのでこの手は使いたくありませんでしたが、
仕方ありませんのでPC内のあらゆるファイル名を出力します。

ログ取得の手順です。
以下の一行をメモ帳にコピーして保存してください。

dir C: /b /a /s > %userprofile%\Desktop\C_Drive.txt

保存が完了しましたらPCをセーフモードで起動させてください。
セーフモードで起動しましたら、スタートボタン⇒すべてのプログラム⇒アクセサリ⇒コマンドプロンプトを右クリックし、
管理者として実行をクリックしてください。
コマンドプロンプトが管理者権限で起動したら、上記で保存したメモ帳を開いてください。
dir C: /b /a /s > %userprofile%\Desktop\C_Drive.txtコマンドをコピーし、右クリックで貼り付けてください。
HDD内部のファイルのスキャンとログ出力が開始されますのでお待ちください。
書き出しが完了すると次のコマンドが入力可能な状態になりますので、
その状態になったらコマンドプロンプトを終了させてください。
該当のログはデスクトップ上にC_Drive.txtと言う名称で出力されます。
ログの出力を確認したらPCを通常モードで再起動し、
出力されたログを私のメールアドレス宛にログファイルごと送信してください。
  • IVNO
  • MAIL
  • 2015/09/07 (Mon) 01:20:56
質問ですが
dir C: /b /a /s > %userprofile%Desktop\C_Drive.txt
このコマンドを張り付けても
「指定されたパスが見つかりません」としか出てきません。
何かこちらで書き換える必要があったのでしょうか?
  • ぐぬぬ
  • 2015/09/07 (Mon) 20:28:29
コマンドが間違っています
時間ないので巻きで行きます。

dir C: /b /a /s > %userprofile%Desktop\C_Drive.txt←誤
dir C: /b /a /s > %userprofile%\Desktop\C_Drive.txt←正

ログをよく見ましょう。
  • IVNO
  • MAIL
  • 2015/09/07 (Mon) 20:59:30
Re: DNSUnlockerの広告等々・・・
メール送信いたしました。
また、前回の状況報告で
IEやGoogleChromeで飛ばされることもなくなったように思えます。
と書きましたが、先ほどIE使用中にまた同じようにReimageRepairに飛ばされました。
そちらの方もよろしくお願いいたします。
  • ぐぬぬ
  • 2015/09/07 (Mon) 21:54:26
微妙です
ログチェックが完了しました。
しかしこれは微妙です。
数は多いのですが、ほぼGoogle Chromeとオマケで少々程度に別の場所から見つかっています。
ともあれ処置しましょう。

メモ帳を起動させ、以下をコピペしてください。
なお、:OTL、:Files、:Commands等はOTLでの処理方法を決める命令文です。
削除なされないようご注意ください。

------コピペこの下より------
:Files
%userprofile%\AppData\Local\Trend Micro
%userprofile%\AppData\Local\{6C5DDAB6-2AC1-485B-9C38-595F30A19238}
%userprofile%\AppData\Local\{9F2F91DD-30B2-4369-97B9-560E0ADF386D}
%userprofile%\AppData\Local\{D1A71253-96E6-400B-AF69-3411A4B07E1B}
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_46238.y.kau.li_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_46238.y.kau.li_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.adlantis.jp_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.adlantis.jp_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_adf.send.microad.jp_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_adf.send.microad.jp_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_advancedpccare.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_advancedpccare.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ams1.ib.adnxs.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ams1.ib.adnxs.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_best.aliexpress.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_best.aliexpress.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_connexity.net_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_connexity.net_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_flirchi.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_flirchi.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_fra1.ib.adnxs.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_fra1.ib.adnxs.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hlamedia.adk2x.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hlamedia.adk2x.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ib.adnxs.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ib.adnxs.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nym1.ib.adnxs.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nym1.ib.adnxs.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_s7.addthis.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_s7.addthis.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_safedownloadsrus146.com.ipaddress.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_safedownloadsrus146.com.ipaddress.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_slimdx.org_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_slimdx.org_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_wanga.me_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_wanga.me_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.advancedpccare.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.advancedpccare.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.pagoda56.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.pagoda56.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.remove-browser-hijacker.com_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.remove-browser-hijacker.com_0.localstorage-journal
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.yac.mx_0.localstorage
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.yac.mx_0.localstorage-journal
%userprofile%\AppData\Roaming\baidu
%userprofile%\Downloads\AdwCleaner.exe
%userprofile%\Downloads\apcsetuprmrt.exe
%userprofile%\Downloads\ccsetup509.exe
%userprofile%\Downloads\mbam-setup-1.75.0.1300.exe

:Commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペこの上まで------

コピペが完了しましたら、分かりやすいお名前をつけて保存してください。
その後、PCをセーフモードで起動させてください。
再度OTLを起動させ、Custom Scan/Fixesの項目内に上記で保存した内容をコピペしてください。
今回は駆除作業のため、その他のチェック項目はありません。
赤い文字の[Run Fix]をクリックして処置を開始してください。
OTLの処置に従って進めてゆき、通常モードで再起動を行う前後いずれかに処置ログが表示されますので、
そちらのログを貼り付けてご連絡ください。
  • IVNO
  • MAIL
  • 2015/09/07 (Mon) 23:17:40
Re: DNSUnlockerの広告等々・・・
返信が遅れてしまい申し訳ありません。
作業終了しました。

以下ログです。

All processes killed
========== FILES ==========
C:\Users\【ユーザー名】\AppData\Local\Trend Micro\Titanium\Cache folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Trend Micro\Titanium folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Trend Micro folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\{6C5DDAB6-2AC1-485B-9C38-595F30A19238} folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\{9F2F91DD-30B2-4369-97B9-560E0ADF386D} folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\{D1A71253-96E6-400B-AF69-3411A4B07E1B} folder moved successfully.
File/Folder C:\Users\【ユーザー名】\AppData\Local\GoogleChrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi not found.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.5_0\_platform_specific\x86-64_ja folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.5_0\_platform_specific folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.5_0\_metadata folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.5_0\audio folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.5_0 folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_46238.y.kau.li_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_46238.y.kau.li_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.adlantis.jp_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.adlantis.jp_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_adf.send.microad.jp_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_adf.send.microad.jp_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_advancedpccare.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_advancedpccare.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ams1.ib.adnxs.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ams1.ib.adnxs.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_best.aliexpress.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_best.aliexpress.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_connexity.net_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_connexity.net_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_flirchi.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_flirchi.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_fra1.ib.adnxs.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_fra1.ib.adnxs.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hlamedia.adk2x.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hlamedia.adk2x.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ib.adnxs.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ib.adnxs.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nym1.ib.adnxs.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nym1.ib.adnxs.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_s7.addthis.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_s7.addthis.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_safedownloadsrus146.com.ipaddress.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_safedownloadsrus146.com.ipaddress.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_slimdx.org_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_slimdx.org_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_wanga.me_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_wanga.me_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.advancedpccare.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.advancedpccare.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.pagoda56.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.pagoda56.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.remove-browser-hijacker.com_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.remove-browser-hijacker.com_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.yac.mx_0.localstorage moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.yac.mx_0.localstorage-journal moved successfully.
C:\Users\【ユーザー名】\AppData\Roaming\baidu folder moved successfully.
File/Folder C:\Users\【ユーザー名】Downloads\AdwCleaner.exe not found.
File/Folder C:\Users\【ユーザー名】Downloads\apcsetuprmrt.exe not found.
File/Folder C:\Users\【ユーザー名】Downloads\ccsetup509.exe not found.
File/Folder C:\Users\【ユーザー名】Downloads\mbam-setup-1.75.0.1300.exe not found.
File\Folder :Commands not found.
File\Folder [purity] not found.
File\Folder [resethosts] not found.
File\Folder [emptyflash] not found.
File\Folder [emptyjava] not found.
File\Folder [emptytemp] not found.
File\Folder [createrestorepoint] not found.
File\Folder [reboot] not found.

OTL by OldTimer - Version 3.2.69.0 log created on 09082015_002418

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ぐぬぬ
  • 2015/09/08 (Tue) 00:32:34
OTLで今一度処置を
OTLはここ最近、ほぼ100%の確率で後半の処置に失敗します。
具体的には:Commands以下の処置に失敗します。
と言うことでそちらの処置だけやり直しましょう。

------コピペこの下より------
:Commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペこの上まで------
  • IVNO
  • MAIL
  • 2015/09/08 (Tue) 01:02:15
Re: DNSUnlockerの広告等々・・・
作業終了しました。
以下ログです。

All processes killed
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: Administrator

User: All Users

User: Default
->Flash cache emptied: 57472 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Default.migrated

User: Guest

User: Public

User: 【ユーザー名】
->Flash cache emptied: 113198 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: Administrator

User: All Users

User: Default

User: Default User

User: Default.migrated

User: Guest

User: Public

User: 【ユーザー名】
->Java cache emptied: 9024212 bytes

Total Java Files Cleaned = 9.00 mb


[EMPTYTEMP]

User: Administrator

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default.migrated

User: Guest

User: Public

User: 【ユーザー名】
->Temp folder emptied: 41193715 bytes
->Temporary Internet Files folder emptied: 813632689 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 392343941 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 21448747 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,210.00 mb

Unable to start System Restore Service. Error code 1084

OTL by OldTimer - Version 3.2.69.0 log created on 09082015_201514

Files\Folders moved on Reboot...
File move failed. C:\Users\【ユーザー名】\AppData\Local\Microsoft\Windows\INetCache\counters.dat scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ぐぬぬ
  • 2015/09/08 (Tue) 20:26:15
MBARとJRTでスキャンを
OTLでの処置は正常に完了した模様です。
現状で主原因がまだ片付いていないため、OTLはまだ保管なされてください。

以下のソフトウェアをご用意ください。

Malwarebytes Anti-Rootkit(通称:MBAR)
http://downloads.malwarebytes.org/file/mbar
クリックするとファイルがダウンロードされますので、わかりやすい場所に保存なされてください。
削除時は本体ごとゴミ箱に入れて削除してください。

Malwarebytes Junkware Removal tool(通称:JRT)
http://downloads.malwarebytes.org/file/jrt
クリックするとファイルがダウンロードされますので、わかりやすい場所に保存なされてください。
削除時は本体ごとゴミ箱に入れて削除してください。

準備ができたら作業を開始いたします。
今回の作業は通常モードのままで結構です。
MBARを起動し、わかりやすい場所に展開を行ってください。
展開が完了すると自動的にソフトウェアが起動します。
Nextをクリックして次に進んでください。
Updateをクリックして最新の定義ファイルに更新を行ってください。
Success: Database was successfully updatedと表示されたらNextをクリックします。
チェックボックス3つ全部にチェックが入っているのを確認し、Scanをクリックします。
スキャンが完了するまで今しばらくお待ちください。
スキャンが完了すると結果が中央に表示されますので、すべてにチェックを入れてCleanupをクリックしてください。
駆除が完了すると再起動を求められますので、Yesをクリックして再起動を行ってください。
再起動が完了しましたらMBARのフォルダの中にmbar-log-(日時).txtというログがありますので、
そちらのログをわかりやすい場所に移動させておいてください。
MBARを終了させ、JRTを起動させてください。
エンターキーなどのキーを押してスキャンを開始します。
検出された場合は再起動するかと問われますが、Nキーを押して再起動はキャンセルしてください。
すべての検出が終わると結果が表示されますので、わかりやすい場所に保存してください。
保存が完了しましたら、一度PCを再起動させてください。
再起動が完了しましたら、MBARとJRTのログを両方とも貼り付けてご連絡をお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/08 (Tue) 20:37:39
Re: DNSUnlockerの広告等々・・・
IVNOの書かれた通りに作業しましたが、
mbarのスキャン結果で「Scan Finished:No malware found!」
と表示されたためか、cleanupをクリックすることがありませんでした。
そのため、再起動も要求されませんでした。

また、フォルダを確認いたしましたところmbar-log-(日時).txtというログではなく、
system-log.txtという物が代わりにありました。こちらを代わりに張り付けるべきでしょうか?

JRTのログはでたので一度そちらだけ張り付けておきます。
以下ログです。

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 10 Home x64
Ran by 【ユーザー名】 on 2015/09/08 at 22:00:33.24
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Chrome


[C:\Users\【ユーザー名】\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\【ユーザー名】\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\【ユーザー名】\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\【ユーザー名】\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2015/09/08 at 22:03:44.55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • ぐぬぬ
  • 2015/09/08 (Tue) 22:22:10
MBARとJRTは削除し再度ACでスキャンを
どちらも検出なしですね。
ログは結構です。
MBARとJRTは不要ですので、導入時の指示に従って削除なされてください。
ここでダメ押しのACでのスキャンを行います。

以下のソフトウェアをご用意ください。

「AdwCleaner」(通称:AC)
http://www.bleepingcomputer.com/download/adwcleaner/dl/125/
ファイル直リンクです。アクセスしてファイルを分かりやすい場所に保存しておいてください。
ソフトウェアを一度起動させることにより自動的にアップデートが始まります。
アップデートが完了しましたら今は何もせずに終了させてください。
本ソフトウェアの削除指示があった際は起動後に「アンインストール」ボタンを押せば自動で削除されます。

準備できたら作業を開始しましょう。

PCをセーフモードで起動させてください。
ACを起動させ、Scanまたはスキャンをクリックします。
スキャンが終了しましたら、Cleaningまたは削除をクリックして掃除を行います。
掃除が完了すると再起動を求められますので、指示に従って通常モードで再起動を行ってください。
これでセーフモードから通常モードに移行します。
再起動前後いずれかにACのログが表示さますので、そちらを貼り付けてご連絡をお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/08 (Tue) 22:26:55
Re: DNSUnlockerの広告等々・・・
ACでの作業完了いたしました。

以下ログです。

# AdwCleaner v5.006 - ログファイルの作成日 08/09/2015 作成時間 22:49:10
# 更新日 06/09/2015 作成元 Xplode
# データベース : 2015-09-07.1 [サーバー]
# オペレーティングシステム : Windows 10 Home (x64)
# ユーザー名 : 【ユーザー名】 - 【ユーザー名】-PC
# 実行場所 : C:\Users\【ユーザー名】\Desktop\AdwCleaner.exe
# オプション : 削除
# サポート : http://toolslib.net/forum

***** [ サービス ] *****


***** [ フォルダ ] *****


***** [ ファイル ] *****

[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage
[-] ファイル 削除済み項目 : C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage-journal

***** [ ショートカット ] *****


***** [ スケジュールタスク ] *****


***** [ レジストリ ] *****


***** [ Webブラウザ ] *****


*************************

:: Winsock設定を初期化しました

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [950 バイト] ##########
  • ぐぬぬ
  • 2015/09/08 (Tue) 22:56:38
ACは削除し現状報告を
ACではGoogle Chromeの一部が処置されています。
私が解析した膨大なログファイルの解析したものと重複するものですね。
見落として削除し忘れたものかもしれません。
ACは不要となりますので、ACを起動させてアンインストールボタンを押して削除なされてください。

PCの状態はいかがでしょうか。
  • IVNO
  • MAIL
  • 2015/09/08 (Tue) 23:01:47
Re: DNSUnlockerの広告等々・・・
IEやChromeでは現象は確認できません。
もっとも、ただ出にくいだけという可能性はありますが。
しかし、報告時から比べると非常にすっきりしました。
本当にありがとうございます。

ただ、MicrosoftEDGEだけは青い文字にカーソルを合わせると相変わらずの広告が出ます。
もう、このブラウザは使わない方がいいですか?
  • ぐぬぬ
  • 2015/09/08 (Tue) 23:17:15
そういう問題ではありません
使わなければ解決するとかの問題ではなく、
現在マルウェアに感染している状態であるならば、いずれ感染が拡大する可能性があるのです。
そのためにはしっかり駆除しなければならないのですが、Windows 10はまだ各種ツールが対応しきれておらず、
その影響もあって駆除がなかなか困難であるのは否めません。
今一度OTLで調査してみましょう。

OTLを起動させる前にブラウザを含め、可能な限りのソフトウェアを終了させてください。
ソフトウェアの終了が完了しましたら、OTLを起動させてください。
表示画面上部中央にあるScan All Usersにチェックを入れてください。
設定が完了しましたら、Custom Scan/Fixesの項目内に以下をコピペしてください。

------コピペこの下より------
SHOWHIDDEN
%windir%\tasks\*.job
DRIVES
BASESERVICES
%SYSTEMDRIVE%\*.exe
ACTIVEX
CREATERESTOREPOINT
------コピペこの上まで------

コピペが完了しましたら、Run Scanをクリックしてスキャンを行ってください。
スキャン完了まで数分程度かかりますので、今しばらくお待ちください。
スキャンが完了しましたら、OTLを保存した場所と同じところに、
OTL.txtとExtras.txtが出力されますので、そちらを貼り付けてご連絡ください。
なお、OTLはその特性上、非常に長文となります。
こちらの掲示板の文字数上限がひらがな換算で約3万文字、英数字換算で約6万文字です。
確実に文字数オーバーとなりますので、余裕を見て5万5千文字程度になるように、
以下のURLの文字数カウンター等で確認しつつ、ログを分割されてご連絡ください。
http://www2u.biglobe.ne.jp/~yuichi/rest/strcount.html
  • IVNO
  • MAIL
  • 2015/09/09 (Wed) 06:38:55
Re: DNSUnlockerの広告等々・・・
返信が遅れてしまい申し訳ありません。
ログの分割完了しました。
以下ログです。

OTL 1/4

OTL logfile created on: 2015/09/09 19:36:17 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\【ユーザー名】\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.10240.16384)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.91 Gb Total Physical Memory | 5.87 Gb Available Physical Memory | 74.16% Memory free
15.91 Gb Paging File | 13.85 Gb Available in Paging File | 87.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.45 Gb Total Space | 215.66 Gb Free Space | 77.17% Space Free | Partition Type: NTFS
Drive D: | 394.18 Gb Total Space | 393.85 Gb Free Space | 99.92% Space Free | Partition Type: NTFS

Computer Name: 【ユーザー名】-PC | User Name: 【ユーザー名】 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - File not found --
PRC - [2015/09/04 20:06:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\【ユーザー名】\Downloads\OTL.exe
PRC - [2015/08/28 20:10:12 | 000,404,064 | ---- | M] (Microsoft Corporation) -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe
PRC - [2015/07/07 20:12:28 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/08/26 19:27:44 | 003,233,806 | ---- | M] () -- C:\Program Files (x86)\Tor\tor.exe
PRC - [2011/08/31 15:33:32 | 001,545,856 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
PRC - [2011/08/24 14:53:24 | 000,100,992 | ---- | M] (ASUS) -- C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe
PRC - [2011/08/24 14:53:22 | 000,092,800 | ---- | M] (ASUS) -- C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
PRC - [2011/07/21 15:49:10 | 005,716,608 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
PRC - [2011/07/18 15:11:42 | 000,166,528 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
PRC - [2011/06/17 17:19:54 | 000,502,704 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
PRC - [2011/06/10 10:49:10 | 002,255,360 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
PRC - [2011/05/30 13:48:18 | 000,082,944 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
PRC - [2011/05/30 13:48:16 | 000,155,648 | ---- | M] (ASUSTeK) -- C:\Windows\SysWOW64\ACEngSvr.exe
PRC - [2011/02/22 13:13:50 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2011/02/22 13:13:46 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2011/01/06 20:08:38 | 000,138,400 | ---- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2010/11/15 10:42:12 | 000,305,792 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
PRC - [2010/10/07 14:05:14 | 000,170,624 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
PRC - [2010/07/09 22:45:00 | 000,984,400 | ---- | M] (Virage Logic Corporation / Sonic Focus) -- C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
PRC - [2009/12/15 10:39:38 | 000,096,896 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
PRC - [2009/06/19 10:29:42 | 000,105,016 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
PRC - [2009/06/19 10:29:26 | 002,488,888 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
PRC - [2009/06/15 17:30:42 | 000,084,536 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
PRC - [2008/12/22 17:15:34 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
PRC - [2008/08/13 21:00:08 | 000,113,208 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2015/08/29 19:04:12 | 000,368,128 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\770ca517afce5fde90d02fa26c89516c\PresentationFramework.Aero.ni.dll
MOD - [2015/08/29 19:03:58 | 014,345,216 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e6ab56f42305525a3a2e473577fc72b\PresentationFramework.ni.dll
MOD - [2015/08/29 19:03:27 | 012,257,792 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\8962b61fa2ab5e6332494153c5a6ab81\PresentationCore.ni.dll
MOD - [2015/08/29 19:03:01 | 003,350,016 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\b5c3bc4a4c105c596c8e65a7d908d8d3\WindowsBase.ni.dll
MOD - [2015/08/28 22:50:40 | 012,438,528 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e3f653c6d321c4c528daa164908e0ff8\System.Windows.Forms.ni.dll
MOD - [2015/08/28 22:50:31 | 001,593,344 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\cebfffe6cee14413d504056227f496b2\System.Drawing.ni.dll
MOD - [2015/08/28 22:50:25 | 000,978,432 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\996056d1eff1504e6304b70484c24115\System.Configuration.ni.dll
MOD - [2015/08/28 22:49:49 | 005,466,624 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\58c73277ac94d5bd748ccafea8b1af02\System.Xml.ni.dll
MOD - [2015/08/28 22:49:45 | 007,994,880 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\b0de8183f9e33cd0fbe10c8db1402653\System.ni.dll
MOD - [2015/08/28 22:49:39 | 011,500,544 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\f87e9c65bcfc0dde0655ce19fb05fe8c\mscorlib.ni.dll
MOD - [2015/07/11 01:28:35 | 000,262,144 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_ja_31bf3856ad364e35\PresentationFramework.resources.dll
MOD - [2015/07/11 01:28:35 | 000,118,784 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\PresentationCore.resources\3.0.0.0_ja_31bf3856ad364e35\PresentationCore.resources.dll
MOD - [2015/07/11 01:28:34 | 000,348,160 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_ja_b77a5c561934e089\mscorlib.resources.dll
MOD - [2011/08/31 15:33:32 | 000,208,384 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
MOD - [2011/06/10 10:49:10 | 001,163,264 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
MOD - [2011/05/30 13:48:14 | 000,009,216 | ---- | M] () -- C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2015/08/28 18:17:58 | 000,280,064 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:57 | 001,031,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorDataService.exe -- (SensorDataService)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 001,420,288 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\UserDataService.dll -- (UserDataSvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 001,203,200 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\Unistore.dll -- (UnistoreSvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 001,169,408 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dosvc.dll -- (DoSvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,343,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\usocore.dll -- (UsoSvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,229,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SensorService.dll -- (SensorService)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,808,856 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,658,568 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ClipSVC.dll -- (ClipSVC)
SRV:[b]64bit:[/b] - [2015/08/28 18:12:49 | 000,084,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:12:39 | 000,026,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mqsvc.exe -- (MSMQ)
SRV:[b]64bit:[/b] - [2015/08/18 15:58:25 | 000,187,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NetSetupSvc.dll -- (NetSetupSvc)
SRV:[b]64bit:[/b] - [2015/08/18 15:55:01 | 002,178,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2015/08/18 15:54:03 | 000,322,048 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2015/08/13 13:22:26 | 002,093,056 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2015/08/11 18:50:47 | 001,643,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:[b]64bit:[/b] - [2015/08/11 18:21:13 | 000,148,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tetheringservice.dll -- (icssvc)
SRV:[b]64bit:[/b] - [2015/08/11 18:07:52 | 000,593,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2015/08/11 18:05:10 | 000,996,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\RDXService.dll -- (RetailDemo)
SRV:[b]64bit:[/b] - [2015/08/03 10:24:19 | 000,503,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\tileobjserver.dll -- (tiledatamodelsvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:10 | 000,621,056 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:10 | 000,504,320 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WalletService.dll -- (WalletService)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:10 | 000,074,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:41 | 000,167,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:38 | 001,844,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:36 | 000,115,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:20 | 000,749,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:16 | 000,075,264 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,526,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,337,408 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,289,280 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\PimIndexMaintenance.dll -- (PimIndexMaintenanceSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wpnservice.dll -- (WpnService)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,033,280 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DevQueryBroker.dll -- (DevQueryBroker)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,027,136 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lfsvc.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 002,674,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\Windows.StateRepository.dll -- (StateRepository)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 001,149,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblGameSave.dll -- (XblGameSave)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 001,019,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XboxNetApiSvc.dll -- (XboxNetApiSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,512,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ngcsvc.dll -- (NgcSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,268,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NgcCtnrSvc.dll -- (NgcCtnrSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,062,464 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\moshost.dll -- (MapsBroker)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,023,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AJRouter.dll -- (AJRouter)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,021,504 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\LicenseManagerSvc.dll -- (LicenseManager)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:06 | 000,134,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\cdpsvc.dll -- (CDPSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:06 | 000,087,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\embeddedmodesvc.dll -- (embeddedmode)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:03 | 003,467,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,918,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\XblAuthManager.dll -- (XblAuthManager)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,836,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,055,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,096,256 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,717,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\usermgr.dll -- (UserManager)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,181,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,296,960 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\APHostService.dll -- (OneSyncSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,196,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dcpsvc.dll -- (DcpSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,027,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe -- (diagnosticshub.standardcollector.service)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,143,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dssvc.dll -- (DsSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,039,856 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\svchost.exe -- (UserDataSvc_Session2)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,039,856 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\svchost.exe -- (UnistoreSvc_Session2)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,039,856 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysNative\svchost.exe -- (PimIndexMaintenanceSvc_Session2)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 000,039,856 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Windows\SysNative\svchost.exe -- (OneSyncSvc_Session2)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:57 | 000,405,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:57 | 000,237,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:56 | 000,019,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:55 | 000,118,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:55 | 000,013,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:54 | 000,275,456 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll -- (EntAppSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,267,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,063,488 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dmwappushsvc.dll -- (dmwappushservice)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:51 | 000,583,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SmsRouterSvc.dll -- (SmsRouter)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,550,400 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,379,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,362,928 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,167,936 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvmsession)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,506,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,024,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:37 | 003,337,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,326,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv)
SRV:[b]64bit:[/b] - [2015/06/03 03:16:46 | 000,249,032 | ---- | M] (Synaptics Incorporated) [Auto | Running] -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe -- (SynTPEnhService)
SRV:[b]64bit:[/b] - [2011/03/03 16:57:58 | 000,379,520 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Stopped] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent)
SRV:[b]64bit:[/b] - [2010/11/29 15:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:[b]64bit:[/b] - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2015/08/28 18:17:54 | 000,925,696 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Unistore.dll -- (UnistoreSvc)
SRV - [2015/08/28 18:17:53 | 000,510,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV - [2015/08/28 18:12:57 | 000,504,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2015/08/28 18:12:57 | 000,504,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2015/08/28 18:12:46 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV - [2015/08/28 18:12:43 | 000,056,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2015/08/12 02:07:16 | 000,269,000 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015/07/10 20:00:30 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\lfsvc.dll -- (lfsvc)
SRV - [2015/07/10 20:00:29 | 002,049,024 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\Windows.StateRepository.dll -- (StateRepository)
SRV - [2015/07/10 20:00:24 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2015/07/10 20:00:23 | 000,193,024 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV - [2015/07/10 19:59:37 | 003,337,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2015/07/07 20:12:28 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2015/06/01 21:00:40 | 000,290,224 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2013/08/26 19:27:44 | 003,233,806 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Tor\tor.exe -- (tor)
SRV - [2011/08/24 14:53:22 | 000,092,800 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe -- (ASUS InstantOn)
SRV - [2011/02/22 13:13:50 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/02/22 13:13:46 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011/01/06 20:08:38 | 000,138,400 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2009/12/15 10:39:38 | 000,096,896 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
SRV - [2009/06/15 17:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2015/08/28 20:08:32 | 000,410,880 | ---- | M] (Realsil Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUer.sys -- (RTSUER)
DRV:[b]64bit:[/b] - [2015/08/28 20:06:45 | 000,599,240 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,934,752 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refsv1.sys -- (ReFSv1)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,061,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,067,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2015/08/28 18:17:53 | 000,046,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmUcsi.sys -- (UcmUcsi)
DRV:[b]64bit:[/b] - [2015/08/28 18:12:56 | 000,175,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mqac.sys -- (MQAC)
DRV:[b]64bit:[/b] - [2015/08/18 16:55:45 | 000,373,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2015/08/11 19:02:56 | 000,080,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2015/08/06 12:17:40 | 000,200,528 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2015/08/06 11:22:03 | 000,685,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdiWiFi.sys -- (wdiwifi)
DRV:[b]64bit:[/b] - [2015/08/03 11:18:37 | 000,046,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2015/08/03 11:17:53 | 000,052,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2015/08/03 11:17:45 | 000,516,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2015/07/11 01:34:25 | 000,038,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2015/07/11 01:34:15 | 000,029,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2015/07/10 20:01:20 | 000,029,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:14 | 000,380,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:14 | 000,215,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,106,520 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRT.sys -- (WindowsTrustedRT)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,061,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UcmCx.sys -- (UcmCx0101)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,031,072 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,200,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,153,440 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,061,952 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\storqosflt.sys -- (storqosflt)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,041,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,026,624 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ioqos.sys -- (IoQos)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:04 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mmcss.sys -- (MMCSS)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,245,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufx01000.sys -- (Ufx01000)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,159,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,077,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,074,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urscx01000.sys -- (UrsCx01000)
DRV:[b]64bit:[/b] - [2015/07/10 20:00:00 | 000,039,264 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cnghwassist.sys -- (cnghwassist)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,155,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,088,928 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:56 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\gpuenergydrv.sys -- (GpuEnergyDrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,129,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,124,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:52 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,119,648 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,082,432 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,291,680 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,209,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Ucx01000.sys -- (Ucx01000)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,127,840 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,098,144 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,083,968 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\filecrypt.sys -- (FileCrypt)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,044,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,044,032 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Udecx.sys -- (UdeCx)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,031,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhf.sys -- (vhf)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,028,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urschipidea.sys -- (UrsChipidea)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\urssynopsys.sys -- (UrsSynopsys)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:40 | 000,017,944 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\WindowsTrustedRTProxy.sys -- (WindowsTrustedRTProxy)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,705,376 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mlx4_bus.sys -- (mlx4_bus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,587,264 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rt640x64.sys -- (rt640x64)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,474,464 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,424,800 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ibbus.sys -- (ibbus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,133,984 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,127,840 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ufxsynopsys.sys -- (ufxsynopsys)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,094,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UfxChipidea.sys -- (UfxChipidea)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,077,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,076,128 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndfltr.sys -- (ndfltr)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,059,232 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winverbs.sys -- (WinVerbs)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,058,720 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas3i.sys -- (percsas3i)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,058,208 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\percsas2i.sys -- (percsas2i)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,055,296 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,040,288 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storufs.sys -- (storufs)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,028,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,026,976 | ---- | M] (Mellanox) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winmad.sys -- (WinMad)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:39 | 000,017,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys -- (swenum)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 003,436,896 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 001,135,456 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,673,120 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,222,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xboxgip.sys -- (xboxgip)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,207,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,116,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\capimg.sys -- (CapImg)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,107,360 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,104,800 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2i.sys -- (LSI_SAS2i)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,099,168 | ---- | M] (Avago Technologies) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3i.sys -- (LSI_SAS3i)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,083,296 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,050,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidinterrupt.sys -- (hidinterrupt)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\buttonconverter.sys -- (buttonconverter)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,026,976 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xinputhid.sys -- (xinputhid)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\genericusbfn.sys -- (genericusbfn)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:38 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,276,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,122,608 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,116,576 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,094,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,092,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,064,000 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,043,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,042,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys -- (CompositeBus)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,038,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fcvsc.sys -- (fcvsc)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2015/07/10 19:59:36 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2015/06/03 03:16:46 | 000,613,576 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2015/06/03 03:16:44 | 000,042,696 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV:[b]64bit:[/b] - [2015/06/01 21:00:18 | 005,384,176 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2013/08/14 03:42:44 | 003,837,440 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athwbx.sys -- (athr)
DRV:[b]64bit:[/b] - [2011/09/22 21:01:54 | 000,311,144 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\RsFx0105.sys -- (RsFx0105)
DRV:[b]64bit:[/b] - [2011/05/13 15:37:54 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:[b]64bit:[/b] - [2011/02/25 17:42:18 | 000,016,768 | ---- | M] (ASUSTek Computer Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AiCharger.sys -- (AiCharger)
DRV:[b]64bit:[/b] - [2011/01/06 20:07:26 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:[b]64bit:[/b] - [2010/11/29 15:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:[b]64bit:[/b] - [2010/11/06 00:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2010/10/15 02:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2010/04/28 09:59:16 | 000,027,264 | ---- | M] (ASUS Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\assd.sys -- (assd)
DRV:[b]64bit:[/b] - [2009/07/20 18:29:40 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
DRV:[b]64bit:[/b] - [2008/05/23 17:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2015/07/10 19:59:39 | 000,017,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys -- (swenum)
DRV - [2015/07/10 19:59:36 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys -- (CompositeBus)
DRV - [2011/09/07 09:55:04 | 000,017,536 | ---- | M] (ASUS) [Kernel | System | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys -- (ATKWMIACPIIO)
DRV - [2009/07/02 17:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7




IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm

IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGNI_jaJP491
IE - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  • ぐぬぬ
  • 2015/09/09 (Wed) 20:09:20
Re: DNSUnlockerの広告等々・・・
OTL 2/4

[color=#E56717]========== FireFox ==========[/color]

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.60.2: C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.60.2: C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@TrendMicro.com/FFExtension: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\【ユーザー名】\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)


[2013/03/26 17:37:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

[color=#E56717]========== Chrome ==========[/color]

CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.0_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
CHR - Extension: No name found = C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\

O1 HOSTS File: ([2015/09/08 20:15:15 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:[b]64bit:[/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:[b]64bit:[/b] - HKU\S-1-5-21-3922431837-200563891-1274897566-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:[b]64bit:[/b] - HKLM..\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" File not found
O4:[b]64bit:[/b] - HKLM..\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe File not found
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\WINDOWS\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ASUSPRP] C:\Program Files (x86)\ASUS\APRP\APRP.EXE (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe (ecareme)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (Virage Logic Corporation / Sonic Focus)
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUS)
O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3922431837-200563891-1274897566-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-3922431837-200563891-1274897566-1000..\Run: [OneDrive] C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab (Microsoft Office Template and Media Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{cfc30fb7-e730-4f6c-ac70-34c05625133f}: DhcpNameServer = 192.168.0.1
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30:[b]64bit:[/b] - LSA: Security Packages - (livessp) - File not found
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {C49181C5-51A7-39B8-A058-B35C7BAD6E1F} - .NET Framework
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\inf\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D3D70DDE-B3B4-33DE-A8CD-808A85D68682} - .NET Framework
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015/09/08 20:58:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2015/09/08 20:57:59 | 000,192,216 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2015/09/08 20:57:02 | 000,109,272 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys
[2015/09/06 12:47:40 | 000,000,000 | ---D | C] -- C:\Program Files\Reason
[2015/09/04 22:26:25 | 000,000,000 | ---D | C] -- C:\_OTL
[2015/09/03 21:38:12 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Malwarebytes
[2015/09/03 21:37:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015/09/02 22:45:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2015/09/02 21:55:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2015/09/02 21:37:41 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Geek Uninstaller
[2015/09/02 21:34:12 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\geek
[2015/09/01 23:59:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2015/09/01 23:59:16 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2015/08/31 01:24:09 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\契約の対価
[2015/08/29 19:57:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AV
[2015/08/29 18:35:17 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\NetworkTiles
[2015/08/29 15:48:40 | 021,875,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2015/08/29 15:48:37 | 018,806,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2015/08/29 15:48:34 | 002,225,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetworkMobileSettings.dll
[2015/08/29 15:48:34 | 001,396,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicenseManager.dll
[2015/08/29 15:48:33 | 008,019,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2015/08/29 15:48:32 | 001,888,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2015/08/29 15:48:32 | 000,963,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LicenseManager.dll
[2015/08/29 15:48:32 | 000,859,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\modernexecserver.dll
[2015/08/29 15:48:31 | 001,593,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2015/08/29 15:48:31 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetSetupShim.dll
[2015/08/29 15:48:30 | 000,609,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2015/08/29 15:48:30 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\NetSetupShim.dll
[2015/08/29 15:48:30 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetSetupSvc.dll
[2015/08/29 15:48:29 | 001,061,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\reseteng.dll
[2015/08/29 15:48:29 | 000,373,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2015/08/29 15:48:29 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BthRadioMedia.dll
[2015/08/29 15:48:29 | 000,077,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2015/08/29 15:48:28 | 001,294,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcnwiz.dll
[2015/08/29 15:48:28 | 001,234,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aitstatic.exe
[2015/08/29 15:48:28 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WlanMediaManager.dll
[2015/08/29 15:48:28 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InstallAgent.exe
[2015/08/29 15:48:28 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnNetsh.dll
[2015/08/29 15:48:28 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wfdprov.dll
[2015/08/29 15:48:27 | 001,226,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wcnwiz.dll
[2015/08/29 15:48:27 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EnterpriseModernAppMgmtCSP.dll
[2015/08/29 15:48:27 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnApi.dll
[2015/08/29 15:48:27 | 000,100,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WcnApi.dll
[2015/08/29 15:48:27 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wfdprov.dll
[2015/08/29 15:48:26 | 002,178,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2015/08/29 15:48:26 | 001,795,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.dll
[2015/08/29 15:48:26 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PackageStateRoaming.dll
[2015/08/29 15:48:26 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafWCN.dll
[2015/08/29 15:48:26 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fdWCN.dll
[2015/08/29 15:48:25 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vaultsvc.dll
[2015/08/29 15:48:25 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PackageStateRoaming.dll
[2015/08/29 00:10:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SleepStudy
[2015/08/28 22:32:39 | 008,613,200 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\SysNative\Windows.Media.Protection.PlayReady.dll
[2015/08/28 22:32:39 | 006,878,256 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
[2015/08/28 22:32:29 | 016,706,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2015/08/28 22:32:21 | 013,024,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2015/08/28 22:32:21 | 003,780,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_nt.dll
[2015/08/28 22:32:17 | 002,415,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2015/08/28 22:32:14 | 003,527,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tquery.dll
[2015/08/28 22:32:13 | 002,558,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssrch.dll
[2015/08/28 22:32:12 | 004,532,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2015/08/28 22:32:12 | 001,212,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RemoteNaturalLanguage.dll
[2015/08/28 22:32:11 | 002,462,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2015/08/28 22:32:11 | 002,416,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2015/08/28 22:32:11 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Speech.dll
[2015/08/28 22:32:10 | 007,523,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2015/08/28 22:32:10 | 001,643,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diagtrack.dll
[2015/08/28 22:32:10 | 001,601,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Speech.dll
[2015/08/28 22:32:10 | 000,898,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\RemoteNaturalLanguage.dll
[2015/08/28 22:32:09 | 004,048,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2015/08/28 22:32:09 | 002,093,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidsvc.dll
[2015/08/28 22:32:09 | 000,595,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LogonController.dll
[2015/08/28 22:32:08 | 002,151,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2015/08/28 22:32:08 | 000,583,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mf.dll
[2015/08/28 22:32:07 | 001,964,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssrch.dll
[2015/08/28 22:32:06 | 000,778,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.dll
[2015/08/28 22:32:06 | 000,644,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsvr.dll
[2015/08/28 22:32:06 | 000,494,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LogonController.dll
[2015/08/28 22:32:05 | 002,748,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tquery.dll
[2015/08/28 22:32:05 | 001,916,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2015/08/28 22:32:05 | 000,996,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RDXService.dll
[2015/08/28 22:32:04 | 003,588,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2015/08/28 22:32:04 | 001,383,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kbase.sys
[2015/08/28 22:32:04 | 000,783,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsvr.dll
[2015/08/28 22:32:04 | 000,586,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
[2015/08/28 22:32:03 | 000,292,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockAppHost.exe
[2015/08/28 22:32:03 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.LockScreen.dll
[2015/08/28 22:32:03 | 000,195,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.LockScreen.dll
[2015/08/28 22:32:02 | 005,454,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2015/08/28 22:32:02 | 000,801,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WWAHost.exe
[2015/08/28 22:32:02 | 000,505,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms2.sys
[2015/08/28 22:32:02 | 000,365,056 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysNative\atmfd.dll
[2015/08/28 22:32:02 | 000,310,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActionCenter.dll
[2015/08/28 22:32:01 | 001,334,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIAutomationCore.dll
[2015/08/28 22:32:01 | 000,700,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WWAHost.exe
[2015/08/28 22:32:01 | 000,303,104 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\atmfd.dll
[2015/08/28 22:32:01 | 000,243,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LockAppHost.exe
[2015/08/28 22:32:01 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SubscriptionMgr.dll
[2015/08/28 22:32:01 | 000,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetworkStatus.dll
[2015/08/28 22:32:00 | 000,918,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2015/08/28 22:32:00 | 000,893,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApiPublic.dll
[2015/08/28 22:32:00 | 000,608,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fontdrvhost.exe
[2015/08/28 22:31:59 | 001,274,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wifinetworkmanager.dll
[2015/08/28 22:31:59 | 000,685,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdiWiFi.sys
[2015/08/28 22:31:59 | 000,554,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\directmanipulation.dll
[2015/08/28 22:31:59 | 000,261,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ActionCenter.dll
[2015/08/28 22:31:59 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinBioDataModel.dll
[2015/08/28 22:31:58 | 001,112,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIAutomationCore.dll
[2015/08/28 22:31:58 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctfuimanager.dll
[2015/08/28 22:31:58 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msctfuimanager.dll
[2015/08/28 22:31:58 | 000,454,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\directmanipulation.dll
[2015/08/28 22:31:58 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationObjFactory.dll
[2015/08/28 22:31:58 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\NotificationObjFactory.dll
[2015/08/28 22:31:57 | 000,593,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmsvc.dll
[2015/08/28 22:31:57 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.Desktop.dll
[2015/08/28 22:31:57 | 000,563,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApi.dll
[2015/08/28 22:31:57 | 000,539,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fontdrvhost.exe
[2015/08/28 22:31:57 | 000,516,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS
[2015/08/28 22:31:56 | 001,087,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2015/08/28 22:31:56 | 000,993,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgent.dll
[2015/08/28 22:31:56 | 000,317,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\configmanager2.dll
[2015/08/28 22:31:56 | 000,200,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wof.sys
[2015/08/28 22:31:56 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationPermissions.dll
[2015/08/28 22:31:56 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VPNv2CSP.dll
[2015/08/28 22:31:55 | 001,822,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2015/08/28 22:31:55 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Notifications.dll
[2015/08/28 22:31:55 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserMgrProxy.dll
[2015/08/28 22:31:55 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
[2015/08/28 22:31:55 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cloudAP.dll
[2015/08/28 22:31:54 | 000,671,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApiPublic.dll
[2015/08/28 22:31:54 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\coredpus.dll
[2015/08/28 22:31:53 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApi.dll
[2015/08/28 22:31:53 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tetheringservice.dll
[2015/08/28 22:31:53 | 000,080,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\stornvme.sys
[2015/08/28 22:31:53 | 000,052,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wpcfltr.sys
[2015/08/28 22:31:52 | 000,642,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdbui.dll
[2015/08/28 22:31:52 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationGeofences.dll
[2015/08/28 22:31:52 | 000,336,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchProtocolHost.exe
[2015/08/28 22:31:52 | 000,159,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserMgrProxy.dll
[2015/08/28 22:31:52 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeParserTask.exe
[2015/08/28 22:31:51 | 000,845,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgent.dll
[2015/08/28 22:31:51 | 000,594,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Shell.Broker.dll
[2015/08/28 22:31:51 | 000,483,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OneDriveSettingSyncProvider.dll
[2015/08/28 22:31:51 | 000,311,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2015/08/28 22:31:51 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\syncutil.dll
[2015/08/28 22:31:51 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationFramework.dll
[2015/08/28 22:31:51 | 000,046,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\msgpiowin32.sys
[2015/08/28 22:31:49 | 000,442,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\storport.sys
[2015/08/28 22:31:49 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2015/08/28 22:31:49 | 000,243,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfps.dll
[2015/08/28 22:31:49 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuautoappupdate.dll
[2015/08/28 22:31:48 | 000,393,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dxgmms1.sys
[2015/08/28 22:31:48 | 000,372,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\OneDriveSettingSyncProvider.dll
[2015/08/28 22:31:48 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tetheringclient.dll
[2015/08/28 22:31:47 | 000,621,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enterprisecsps.dll
[2015/08/28 22:31:47 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tetheringclient.dll
[2015/08/28 22:31:45 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GamePanel.exe
[2015/08/28 22:31:45 | 000,384,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockAppBroker.dll
[2015/08/28 22:31:45 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Core.TextInput.dll
[2015/08/28 22:31:45 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssprxy.dll
[2015/08/28 22:31:45 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationFrameworkInternalPS.dll
[2015/08/28 22:31:44 | 001,290,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Shell.dll
[2015/08/28 22:31:44 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GamePanel.exe
[2015/08/28 22:31:44 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/08/28 22:31:44 | 000,311,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LockAppBroker.dll
[2015/08/28 22:31:44 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/08/28 22:31:44 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SharedStartModelShim.dll
[2015/08/28 22:31:44 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReInfo.dll
[2015/08/28 22:31:43 | 000,911,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SharedStartModel.dll
[2015/08/28 22:31:43 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tileobjserver.dll
[2015/08/28 22:31:43 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VEEventDispatcher.dll
[2015/08/28 22:31:42 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VEEventDispatcher.dll
[2015/08/28 22:31:42 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_UserAccount.dll
[2015/08/28 22:31:42 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VEDataLayerHelpers.dll
[2015/08/28 22:31:42 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VEDataLayerHelpers.dll
[2015/08/28 20:08:40 | 000,000,000 | R--D | C] -- C:\Users\【ユーザー名】\OneDrive
[2015/08/28 20:08:32 | 009,898,752 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SysWow64\RsCRIcon.dll
[2015/08/28 20:06:58 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\MicrosoftEdge
[2015/08/28 20:06:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Atheros
[2015/08/28 20:06:45 | 000,599,240 | ---- | C] (Qualcomm Atheros) -- C:\WINDOWS\SysNative\drivers\btfilter.sys
[2015/08/28 20:06:45 | 000,011,264 | ---- | C] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll.muien-US
[2015/08/28 20:06:44 | 000,182,784 | ---- | C] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll
[2015/08/28 20:06:44 | 000,181,760 | ---- | C] (Qualcomm Atheros Communications Inc.) -- C:\WINDOWS\SysNative\btcoinst.dll
[2015/08/28 20:06:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft OneDrive
[2015/08/28 20:05:53 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Comms
[2015/08/28 20:05:18 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Publishers
[2015/08/28 20:03:00 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\TileDataLayer
[2015/08/28 19:01:57 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favorites
[2015/08/28 18:55:03 | 002,718,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintConfig.dll
[2015/08/28 18:41:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SpeechEngines
[2015/08/28 18:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2015/08/28 18:34:27 | 000,000,000 | --SD | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft
[2015/08/28 18:34:27 | 000,000,000 | R-SD | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
[2015/08/28 18:34:27 | 000,000,000 | R--D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2015/08/28 18:34:27 | 000,000,000 | R--D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2015/08/28 18:34:27 | 000,000,000 | R--D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\スタート メニュー
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\AppData\Local\Temporary Internet Files
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Templates
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\SendTo
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Recent
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\PrintHood
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\NetHood
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Documents\My Videos
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Documents\My Pictures
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Documents\My Music
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\My Documents
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Local Settings
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\AppData\Local\History
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Cookies
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\Application Data
[2015/08/28 18:34:27 | 000,000,000 | -HSD | C] -- C:\Users\【ユーザー名】\AppData\Local\Application Data
[2015/08/28 18:34:27 | 000,000,000 | -H-D | C] -- C:\Users\【ユーザー名】\AppData
[2015/08/28 18:34:27 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Temp
[2015/08/28 18:34:27 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft
[2015/08/28 18:34:27 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2015/08/28 18:31:03 | 000,000,000 | ---D | C] -- C:\ProgramData\SonicFocus
[2015/08/28 18:30:51 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2015/08/28 18:30:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RTCOM
[2015/08/28 18:30:44 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2015/08/28 18:30:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sda
[2015/08/28 18:26:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2015/08/28 18:24:34 | 000,000,000 | -HSD | C] -- C:\Recovery
[2015/08/28 18:18:06 | 001,561,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll
[2015/08/28 18:18:06 | 001,356,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll
[2015/08/28 18:18:06 | 000,569,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MCRecvSrc.dll
[2015/08/28 18:18:06 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToManager.dll
[2015/08/28 18:18:06 | 000,480,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MCRecvSrc.dll
[2015/08/28 18:18:06 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcastdvr.exe
[2015/08/28 18:17:58 | 014,241,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmp.dll
[2015/08/28 18:17:58 | 012,589,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmp.dll
[2015/08/28 18:17:58 | 004,791,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2015/08/28 18:17:58 | 003,248,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2015/08/28 18:17:58 | 002,646,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2015/08/28 18:17:58 | 001,562,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll
[2015/08/28 18:17:58 | 001,411,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Editing.dll
[2015/08/28 18:17:58 | 001,043,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Editing.dll
[2015/08/28 18:17:58 | 001,043,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2015/08/28 18:17:58 | 001,025,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsrcsnk.dll
[2015/08/28 18:17:58 | 000,980,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SecConfig.efi
[2015/08/28 18:17:58 | 000,896,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsrcsnk.dll
[2015/08/28 18:17:58 | 000,877,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2015/08/28 18:17:58 | 000,846,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpncore.dll
[2015/08/28 18:17:58 | 000,816,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmpeg2srcsnk.dll
[2015/08/28 18:17:58 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpccpl.dll
[2015/08/28 18:17:58 | 000,713,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
[2015/08/28 18:17:58 | 000,670,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieproxy.dll
[2015/08/28 18:17:58 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpnapps.dll
[2015/08/28 18:17:58 | 000,584,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Sensors.dll
[2015/08/28 18:17:58 | 000,527,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2015/08/28 18:17:58 | 000,521,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PsmServiceExtHost.dll
[2015/08/28 18:17:58 | 000,501,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2015/08/28 18:17:58 | 000,487,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmkvsrcsnk.dll
[2015/08/28 18:17:58 | 000,473,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wpnapps.dll
[2015/08/28 18:17:58 | 000,437,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Sensors.dll
[2015/08/28 18:17:58 | 000,373,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmkvsrcsnk.dll
[2015/08/28 18:17:58 | 000,333,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFPlay.dll
[2015/08/28 18:17:58 | 000,310,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsApi.dll
[2015/08/28 18:17:58 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieproxy.dll
[2015/08/28 18:17:58 | 000,285,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFPlay.dll
[2015/08/28 18:17:58 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2015/08/28 18:17:58 | 000,251,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsApi.dll
[2015/08/28 18:17:58 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fwpolicyiomgr.dll
[2015/08/28 18:17:58 | 000,163,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fwpolicyiomgr.dll
[2015/08/28 18:17:58 | 000,082,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcd.dll
[2015/08/28 18:17:57 | 011,557,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2015/08/28 18:17:57 | 009,889,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2015/08/28 18:17:57 | 006,305,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2015/08/28 18:17:57 | 004,760,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ExplorerFrame.dll
[2015/08/28 18:17:57 | 004,398,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2015/08/28 18:17:57 | 004,350,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ExplorerFrame.dll
[2015/08/28 18:17:57 | 004,169,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbon.dll
[2015/08/28 18:17:57 | 003,443,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbon.dll
[2015/08/28 18:17:57 | 002,147,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d9.dll
[2015/08/28 18:17:57 | 001,773,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Immersive.dll
[2015/08/28 18:17:57 | 001,611,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll
[2015/08/28 18:17:57 | 001,201,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Cred.dll
[2015/08/28 18:17:57 | 001,200,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpcrt4.dll
[2015/08/28 18:17:57 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorDataService.exe
[2015/08/28 18:17:57 | 000,872,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntshrui.dll
[2015/08/28 18:17:57 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2015/08/28 18:17:57 | 000,754,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Cred.dll
[2015/08/28 18:17:57 | 000,589,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uxtheme.dll
[2015/08/28 18:17:57 | 000,589,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\efscore.dll
[2015/08/28 18:17:57 | 000,584,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbonRes.dll
[2015/08/28 18:17:57 | 000,584,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbonRes.dll
[2015/08/28 18:17:57 | 000,584,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wimgapi.dll
[2015/08/28 18:17:57 | 000,542,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2015/08/28 18:17:57 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.BlockedShutdown.dll
[2015/08/28 18:17:57 | 000,414,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.BioFeedback.dll
[2015/08/28 18:17:57 | 000,407,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CredProvDataModel.dll
[2015/08/28 18:17:57 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\stobject.dll
[2015/08/28 18:17:57 | 000,335,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CredProvDataModel.dll
[2015/08/28 18:17:57 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.BlockedShutdown.dll
[2015/08/28 18:17:57 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConhostV2.dll
[2015/08/28 18:17:57 | 000,291,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\systemcpl.dll
[2015/08/28 18:17:57 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.BioFeedback.dll
[2015/08/28 18:17:57 | 000,279,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\systemcpl.dll
[2015/08/28 18:17:57 | 000,271,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConsoleLogon.dll
[2015/08/28 18:17:57 | 000,252,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ContentDeliveryManager.Utilities.dll
[2015/08/28 18:17:57 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DevicesFlowBroker.dll
[2015/08/28 18:17:57 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shutdownux.dll
[2015/08/28 18:17:57 | 000,181,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2015/08/28 18:17:57 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_SignInOptions.dll
[2015/08/28 18:17:57 | 000,179,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srumsvc.dll
[2015/08/28 18:17:57 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Privacy.dll
[2015/08/28 18:17:57 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sendmail.dll
[2015/08/28 18:17:57 | 000,104,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sendmail.dll
[2015/08/28 18:17:57 | 000,097,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcd.dll
[2015/08/28 18:17:57 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\spbcd.dll
[2015/08/28 18:17:57 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.ProxyStub.dll
[2015/08/28 18:17:57 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.OneCore.dll
[2015/08/28 18:17:57 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.PAL.Desktop.dll
[2015/08/28 18:17:57 | 000,045,568 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysNative\atmlib.dll
[2015/08/28 18:17:57 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\calc.exe
[2015/08/28 18:17:57 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\calc.exe
[2015/08/28 18:17:54 | 007,569,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mos.dll
[2015/08/28 18:17:54 | 007,051,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BingMaps.dll
[2015/08/28 18:17:54 | 006,101,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mos.dll
[2015/08/28 18:17:54 | 005,118,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\windows.storage.dll
[2015/08/28 18:17:54 | 005,076,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BingMaps.dll
[2015/08/28 18:17:54 | 003,362,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2015/08/28 18:17:54 | 001,591,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2015/08/28 18:17:54 | 001,521,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActiveSyncProvider.dll
[2015/08/28 18:17:54 | 001,420,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserDataService.dll
[2015/08/28 18:17:54 | 001,418,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RecoveryDrive.exe
[2015/08/28 18:17:54 | 001,417,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2015/08/28 18:17:54 | 001,294,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2015/08/28 18:17:54 | 001,203,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Unistore.dll
[2015/08/28 18:17:54 | 001,169,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dosvc.dll
[2015/08/28 18:17:54 | 001,135,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipUp.exe
[2015/08/28 18:17:54 | 001,123,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2015/08/28 18:17:54 | 001,018,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2015/08/28 18:17:54 | 000,934,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\refsv1.sys
[2015/08/28 18:17:54 | 000,925,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Unistore.dll
[2015/08/28 18:17:54 | 000,869,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapControlCore.dll
[2015/08/28 18:17:54 | 000,858,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2015/08/28 18:17:54 | 000,856,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ContactApis.dll
[2015/08/28 18:17:54 | 000,832,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapsStore.dll
[2015/08/28 18:17:54 | 000,783,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2015/08/28 18:17:54 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\efscore.dll
[2015/08/28 18:17:54 | 000,695,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimgapi.dll
[2015/08/28 18:17:54 | 000,654,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PlayToManager.dll
[2015/08/28 18:17:54 | 000,632,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2015/08/28 18:17:54 | 000,630,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2015/08/28 18:17:54 | 000,623,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ContactApis.dll
[2015/08/28 18:17:54 | 000,578,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winlogon.exe
[2015/08/28 18:17:54 | 000,521,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimserv.exe
[2015/08/28 18:17:54 | 000,494,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StoreAgent.dll
[2015/08/28 18:17:54 | 000,446,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapConfiguration.dll
[2015/08/28 18:17:54 | 000,430,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcomapi.dll
[2015/08/28 18:17:54 | 000,425,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2015/08/28 18:17:54 | 000,416,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2015/08/28 18:17:54 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuuhext.dll
[2015/08/28 18:17:54 | 000,359,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncsi.dll
[2015/08/28 18:17:54 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usocore.dll
[2015/08/28 18:17:54 | 000,342,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcastdvr.exe
[2015/08/28 18:17:54 | 000,329,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusUpdateHandlers.dll
[2015/08/28 18:17:54 | 000,328,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MapConfiguration.dll
[2015/08/28 18:17:54 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MBMediaManager.dll
[2015/08/28 18:17:54 | 000,290,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wininit.exe
[2015/08/28 18:17:54 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provhandlers.dll
[2015/08/28 18:17:54 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provengine.dll
[2015/08/28 18:17:54 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\updatehandlers.dll
[2015/08/28 18:17:54 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorService.dll
[2015/08/28 18:17:54 | 000,208,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2015/08/28 18:17:54 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srumsvc.dll
[2015/08/28 18:17:54 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmcsp.dll
[2015/08/28 18:17:54 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OmaDmAgent.dll
[2015/08/28 18:17:54 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReInfo.dll
[2015/08/28 18:17:54 | 000,187,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provisioningcsp.dll
[2015/08/28 18:17:54 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BootMenuUX.dll
[2015/08/28 18:17:54 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\psmsrv.dll
[2015/08/28 18:17:54 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdboot.exe
[2015/08/28 18:17:54 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storewuauth.dll
[2015/08/28 18:17:54 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotification.exe
[2015/08/28 18:17:54 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VEStoreEventHandlers.dll
  • ぐぬぬ
  • 2015/09/09 (Wed) 20:11:12
Re: DNSUnlockerの広告等々・・・
OTL 3/4

[2015/08/28 18:17:54 | 000,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\omadmclient.exe
[2015/08/28 18:17:54 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsNativeApi.V2.dll
[2015/08/28 18:17:54 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spbcd.dll
[2015/08/28 18:17:54 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2015/08/28 18:17:54 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsNativeApi.V2.dll
[2015/08/28 18:17:54 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\setbcdlocale.dll
[2015/08/28 18:17:54 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\unenrollhook.dll
[2015/08/28 18:17:54 | 000,061,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dam.sys
[2015/08/28 18:17:54 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hmkd.dll
[2015/08/28 18:17:54 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotificationUx.exe
[2015/08/28 18:17:54 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\omadmprc.exe
[2015/08/28 18:17:54 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\hmkd.dll
[2015/08/28 18:17:54 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VoiceActivationManager.dll
[2015/08/28 18:17:54 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicenseManagerShellext.exe
[2015/08/28 18:17:53 | 006,488,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\windows.storage.dll
[2015/08/28 18:17:53 | 004,611,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2015/08/28 18:17:53 | 003,248,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msftedit.dll
[2015/08/28 18:17:53 | 002,606,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msftedit.dll
[2015/08/28 18:17:53 | 002,125,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.appcore.dll
[2015/08/28 18:17:53 | 001,714,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.appcore.dll
[2015/08/28 18:17:53 | 001,203,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Bluetooth.dll
[2015/08/28 18:17:53 | 001,101,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2015/08/28 18:17:53 | 000,966,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.appcore.dll
[2015/08/28 18:17:53 | 000,841,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Import.dll
[2015/08/28 18:17:53 | 000,828,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Bluetooth.dll
[2015/08/28 18:17:53 | 000,823,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2015/08/28 18:17:53 | 000,808,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CoreMessaging.dll
[2015/08/28 18:17:53 | 000,762,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinapi.appcore.dll
[2015/08/28 18:17:53 | 000,680,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Connectivity.dll
[2015/08/28 18:17:53 | 000,679,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppContracts.dll
[2015/08/28 18:17:53 | 000,677,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2015/08/28 18:17:53 | 000,658,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipSVC.dll
[2015/08/28 18:17:53 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MessagingDataModel2.dll
[2015/08/28 18:17:53 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Import.dll
[2015/08/28 18:17:53 | 000,518,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationController.dll
[2015/08/28 18:17:53 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CoreMessaging.dll
[2015/08/28 18:17:53 | 000,503,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.Connectivity.dll
[2015/08/28 18:17:53 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MessagingDataModel2.dll
[2015/08/28 18:17:53 | 000,441,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppContracts.dll
[2015/08/28 18:17:53 | 000,421,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Bluetooth.dll
[2015/08/28 18:17:53 | 000,335,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wintrust.dll
[2015/08/28 18:17:53 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Internal.Bluetooth.dll
[2015/08/28 18:17:53 | 000,263,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DisplayManager.dll
[2015/08/28 18:17:53 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DisplayManager.dll
[2015/08/28 18:17:53 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmapi.dll
[2015/08/28 18:17:53 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ACPBackgroundManagerPolicy.dll
[2015/08/28 18:17:53 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbser.sys
[2015/08/28 18:17:53 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\bthhfenum.sys
[2015/08/28 18:17:53 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UcmUcsi.sys
[2015/08/28 18:17:53 | 000,037,376 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysWow64\atmlib.dll
[2015/08/28 18:17:53 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VoiceActivationManager.dll
[2015/08/28 18:17:53 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationControllerPS.dll
[2015/08/28 18:13:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\XPSViewer
[2015/08/28 18:13:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\msmq
[2015/08/28 18:13:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\BestPractices
[2015/08/28 18:13:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\BestPractices
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2015/08/28 18:13:06 | 000,000,000 | ---D | C] -- C:\inetpub
[2015/08/28 18:12:18 | 000,778,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationNative_v0300.dll
[2015/08/28 18:12:18 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2015/08/28 18:12:18 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TsWpfWrp.exe
[2015/08/28 18:12:14 | 001,166,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationNative_v0300.dll
[2015/08/28 18:12:14 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2015/08/28 18:12:14 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TsWpfWrp.exe
[2015/08/28 02:18:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2015/08/28 02:17:46 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Sun
[2015/08/28 02:17:44 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\.oracle_jre_usage
[2015/08/26 23:25:23 | 000,000,000 | ---D | C] -- C:\ProgramData\IntelDLM
[2015/08/26 23:19:58 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Intel
[2015/08/26 23:19:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver Update Utility
[2015/08/26 23:19:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel Driver Update Utility
[2015/08/26 23:19:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2015/08/26 23:12:52 | 005,069,632 | ---- | C] (Intel) -- C:\Users\【ユーザー名】\Desktop\Intel Driver Update Utility Installer.exe
[2015/08/24 17:24:39 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2015/08/24 17:24:39 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\MFAData
[2015/08/24 17:24:39 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2015/08/24 17:24:39 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Local\Avg2015
[2015/08/22 23:38:49 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\The Last of Lolita escape
[2015/08/22 23:35:20 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\rushbattle
[2015/08/16 22:32:28 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\Desktop\asunana-ver1-02
[2015/08/13 02:11:21 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MsSpellCheckingFacility.exe
[2015/08/13 02:11:18 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmlmedia.dll
[2015/08/13 02:11:13 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmlmedia.dll
[2015/08/13 02:04:57 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wu.upgrade.ps.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2015/09/09 19:33:50 | 000,016,148 | ---- | M] () -- C:\WINDOWS\SysNative\【ユーザー名】-PC_【ユーザー名】_HistoryPrediction.bin
[2015/09/09 19:08:00 | 000,000,714 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2015/09/09 19:07:00 | 000,000,626 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2015/09/09 15:16:58 | 000,000,710 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2015/09/09 15:12:35 | 2076,831,743 | -HS- | M] () -- C:\hiberfil.sys
[2015/09/09 15:12:35 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2015/09/08 22:56:48 | 001,926,530 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2015/09/08 22:56:48 | 000,890,860 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2015/09/08 22:56:48 | 000,631,044 | ---- | M] () -- C:\WINDOWS\SysNative\perfh011.dat
[2015/09/08 22:56:48 | 000,196,696 | ---- | M] () -- C:\WINDOWS\SysNative\perfc011.dat
[2015/09/08 22:56:48 | 000,196,668 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2015/09/08 22:52:32 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015/09/08 22:50:42 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2015/09/08 20:57:59 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2015/09/08 20:57:02 | 000,109,272 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys
[2015/09/08 20:15:15 | 000,000,098 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\etc\Hosts
[2015/09/07 20:17:42 | 005,858,092 | ---- | M] () -- C:\Users\【ユーザー名】\%userprofile
[2015/09/04 19:11:00 | 000,002,344 | ---- | M] () -- C:\Users\【ユーザー名】\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/09/04 19:11:00 | 000,002,320 | ---- | M] () -- C:\Users\【ユーザー名】\Desktop\Google Chrome.lnk
[2015/09/02 21:46:05 | 000,002,126 | ---- | M] () -- C:\Users\Public\Desktop\Acrobat Reader DC.lnk
[2015/09/02 21:27:18 | 000,002,154 | ---- | M] () -- C:\WINDOWS\SysNative\AutoRunFilter.ini
[2015/09/01 23:59:27 | 000,000,865 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015/08/31 16:11:39 | 000,000,085 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2015/08/30 22:49:47 | 000,001,345 | ---- | M] () -- C:\WINDOWS\SysNative\ServiceFilter.ini
[2015/08/29 02:30:00 | 000,406,152 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2015/08/28 20:08:32 | 009,898,752 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SysWow64\RsCRIcon.dll
[2015/08/28 20:08:32 | 000,410,880 | ---- | M] (Realsil Semiconductor Corporation) -- C:\WINDOWS\SysNative\drivers\RtsUer.sys
[2015/08/28 20:08:32 | 000,091,904 | ---- | M] (Realtek Semiconductor.) -- C:\WINDOWS\SysNative\RtCRX64.dll
[2015/08/28 20:06:45 | 000,599,240 | ---- | M] (Qualcomm Atheros) -- C:\WINDOWS\SysNative\drivers\btfilter.sys
[2015/08/28 20:06:45 | 000,182,784 | ---- | M] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll
[2015/08/28 20:06:45 | 000,011,264 | ---- | M] (Qualcomm®Atheros®) -- C:\WINDOWS\SysNative\BtContextMenu.dll.muien-US
[2015/08/28 20:06:45 | 000,001,926 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0xf0.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x21.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x11.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40.dfu
[2015/08/28 20:06:45 | 000,001,922 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010100_40.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40_SS01.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40_nf01.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40.dfu
[2015/08/28 20:06:45 | 000,001,796 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020000_40.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_SS01.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_LV01.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0xf1.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x22.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x12.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,512 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010100_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,242 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,228 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x04.dfu
[2015/08/28 20:06:45 | 000,001,214 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x03.dfu
[2015/08/28 20:06:45 | 000,001,204 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2015/08/28 20:06:45 | 000,001,204 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40.dfu
[2015/08/28 20:06:45 | 000,001,198 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26.dfu
[2015/08/28 20:06:45 | 000,001,192 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26_0x01.dfu
[2015/08/28 20:06:45 | 000,000,296 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x01.dfu
[2015/08/28 20:06:45 | 000,000,278 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x04.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x03.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x02.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26_0x01.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26.dfu
[2015/08/28 20:06:44 | 000,246,804 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AtherosBT.bin
[2015/08/28 20:06:44 | 000,181,760 | ---- | M] (Qualcomm Atheros Communications Inc.) -- C:\WINDOWS\SysNative\btcoinst.dll
[2015/08/28 20:06:44 | 000,048,092 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020200.dfu
[2015/08/28 20:06:44 | 000,046,748 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010000.dfu
[2015/08/28 20:06:44 | 000,046,268 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020100.dfu
[2015/08/28 20:06:44 | 000,046,212 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020000.dfu
[2015/08/28 20:06:44 | 000,040,684 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010000_ss01.dfu
[2015/08/28 20:06:44 | 000,038,140 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010100.dfu
[2015/08/28 20:06:44 | 000,023,532 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020201.dfu
[2015/08/28 20:05:46 | 000,045,056 | ---- | M] () -- C:\WINDOWS\SysWow64\acovcnt.exe
[2015/08/28 19:01:20 | 000,010,449 | ---- | M] () -- C:\WINDOWS\diagerr.xml
[2015/08/28 19:01:20 | 000,009,528 | ---- | M] () -- C:\WINDOWS\diagwrn.xml
[2015/08/28 19:00:28 | 000,023,208 | ---- | M] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2015/08/28 18:33:07 | 001,667,602 | ---- | M] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2015/08/28 18:31:12 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01011.Wdf
[2015/08/28 18:30:46 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
[2015/08/28 18:18:06 | 001,561,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winmde.dll
[2015/08/28 18:18:06 | 001,356,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winmde.dll
[2015/08/28 18:18:06 | 000,569,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MCRecvSrc.dll
[2015/08/28 18:18:06 | 000,497,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToManager.dll
[2015/08/28 18:18:06 | 000,480,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MCRecvSrc.dll
[2015/08/28 18:18:06 | 000,275,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcastdvr.exe
[2015/08/28 18:17:58 | 014,241,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmp.dll
[2015/08/28 18:17:58 | 012,589,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmp.dll
[2015/08/28 18:17:58 | 004,791,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2015/08/28 18:17:58 | 003,248,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.dll
[2015/08/28 18:17:58 | 002,646,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.dll
[2015/08/28 18:17:58 | 001,562,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmpmde.dll
[2015/08/28 18:17:58 | 001,411,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Editing.dll
[2015/08/28 18:17:58 | 001,043,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Editing.dll
[2015/08/28 18:17:58 | 001,043,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmp4srcsnk.dll
[2015/08/28 18:17:58 | 001,025,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsrcsnk.dll
[2015/08/28 18:17:58 | 000,980,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SecConfig.efi
[2015/08/28 18:17:58 | 000,896,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsrcsnk.dll
[2015/08/28 18:17:58 | 000,877,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmp4srcsnk.dll
[2015/08/28 18:17:58 | 000,846,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpncore.dll
[2015/08/28 18:17:58 | 000,816,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmpeg2srcsnk.dll
[2015/08/28 18:17:58 | 000,799,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpccpl.dll
[2015/08/28 18:17:58 | 000,713,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmpeg2srcsnk.dll
[2015/08/28 18:17:58 | 000,670,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieproxy.dll
[2015/08/28 18:17:58 | 000,599,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpnapps.dll
[2015/08/28 18:17:58 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Sensors.dll
[2015/08/28 18:17:58 | 000,527,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioSes.dll
[2015/08/28 18:17:58 | 000,521,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PsmServiceExtHost.dll
[2015/08/28 18:17:58 | 000,501,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEng.dll
[2015/08/28 18:17:58 | 000,487,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfmkvsrcsnk.dll
[2015/08/28 18:17:58 | 000,473,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wpnapps.dll
[2015/08/28 18:17:58 | 000,437,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Sensors.dll
[2015/08/28 18:17:58 | 000,373,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfmkvsrcsnk.dll
[2015/08/28 18:17:58 | 000,333,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFPlay.dll
[2015/08/28 18:17:58 | 000,310,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsApi.dll
[2015/08/28 18:17:58 | 000,294,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieproxy.dll
[2015/08/28 18:17:58 | 000,285,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFPlay.dll
[2015/08/28 18:17:58 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AudioEndpointBuilder.dll
[2015/08/28 18:17:58 | 000,251,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsApi.dll
[2015/08/28 18:17:58 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fwpolicyiomgr.dll
[2015/08/28 18:17:58 | 000,163,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fwpolicyiomgr.dll
[2015/08/28 18:17:58 | 000,097,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcd.dll
[2015/08/28 18:17:58 | 000,082,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcd.dll
[2015/08/28 18:17:57 | 011,557,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2015/08/28 18:17:57 | 009,889,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2015/08/28 18:17:57 | 006,305,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2015/08/28 18:17:57 | 004,760,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ExplorerFrame.dll
[2015/08/28 18:17:57 | 004,398,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2015/08/28 18:17:57 | 004,350,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ExplorerFrame.dll
[2015/08/28 18:17:57 | 004,169,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbon.dll
[2015/08/28 18:17:57 | 003,443,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbon.dll
[2015/08/28 18:17:57 | 002,147,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d9.dll
[2015/08/28 18:17:57 | 001,773,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Immersive.dll
[2015/08/28 18:17:57 | 001,611,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll
[2015/08/28 18:17:57 | 001,201,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Cred.dll
[2015/08/28 18:17:57 | 001,200,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpcrt4.dll
[2015/08/28 18:17:57 | 001,031,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorDataService.exe
[2015/08/28 18:17:57 | 000,872,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntshrui.dll
[2015/08/28 18:17:57 | 000,850,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comdlg32.dll
[2015/08/28 18:17:57 | 000,754,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Cred.dll
[2015/08/28 18:17:57 | 000,589,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\uxtheme.dll
[2015/08/28 18:17:57 | 000,589,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\efscore.dll
[2015/08/28 18:17:57 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIRibbonRes.dll
[2015/08/28 18:17:57 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIRibbonRes.dll
[2015/08/28 18:17:57 | 000,584,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wimgapi.dll
[2015/08/28 18:17:57 | 000,542,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2015/08/28 18:17:57 | 000,485,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.BlockedShutdown.dll
[2015/08/28 18:17:57 | 000,414,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.BioFeedback.dll
[2015/08/28 18:17:57 | 000,407,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CredProvDataModel.dll
[2015/08/28 18:17:57 | 000,356,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\stobject.dll
[2015/08/28 18:17:57 | 000,335,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CredProvDataModel.dll
[2015/08/28 18:17:57 | 000,322,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.BlockedShutdown.dll
[2015/08/28 18:17:57 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConhostV2.dll
[2015/08/28 18:17:57 | 000,291,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\systemcpl.dll
[2015/08/28 18:17:57 | 000,283,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.BioFeedback.dll
[2015/08/28 18:17:57 | 000,279,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\systemcpl.dll
[2015/08/28 18:17:57 | 000,271,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ConsoleLogon.dll
[2015/08/28 18:17:57 | 000,252,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ContentDeliveryManager.Utilities.dll
[2015/08/28 18:17:57 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DevicesFlowBroker.dll
[2015/08/28 18:17:57 | 000,181,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shutdownux.dll
[2015/08/28 18:17:57 | 000,181,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2015/08/28 18:17:57 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_SignInOptions.dll
[2015/08/28 18:17:57 | 000,179,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\srumsvc.dll
[2015/08/28 18:17:57 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Privacy.dll
[2015/08/28 18:17:57 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sendmail.dll
[2015/08/28 18:17:57 | 000,104,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sendmail.dll
[2015/08/28 18:17:57 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\spbcd.dll
[2015/08/28 18:17:57 | 000,068,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.ProxyStub.dll
[2015/08/28 18:17:57 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.OneCore.dll
[2015/08/28 18:17:57 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Cortana.PAL.Desktop.dll
[2015/08/28 18:17:57 | 000,045,568 | ---- | M] (Adobe Systems) -- C:\WINDOWS\SysNative\atmlib.dll
[2015/08/28 18:17:57 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\calc.exe
[2015/08/28 18:17:57 | 000,031,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\calc.exe
[2015/08/28 18:17:54 | 007,569,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mos.dll
[2015/08/28 18:17:54 | 007,051,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BingMaps.dll
[2015/08/28 18:17:54 | 006,101,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mos.dll
[2015/08/28 18:17:54 | 005,118,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\windows.storage.dll
[2015/08/28 18:17:54 | 005,076,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\BingMaps.dll
[2015/08/28 18:17:54 | 003,362,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2015/08/28 18:17:54 | 001,591,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2015/08/28 18:17:54 | 001,521,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActiveSyncProvider.dll
[2015/08/28 18:17:54 | 001,420,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserDataService.dll
[2015/08/28 18:17:54 | 001,418,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RecoveryDrive.exe
[2015/08/28 18:17:54 | 001,417,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2015/08/28 18:17:54 | 001,294,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2015/08/28 18:17:54 | 001,203,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Unistore.dll
[2015/08/28 18:17:54 | 001,169,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dosvc.dll
[2015/08/28 18:17:54 | 001,135,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipUp.exe
[2015/08/28 18:17:54 | 001,123,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2015/08/28 18:17:54 | 001,018,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2015/08/28 18:17:54 | 000,934,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\refsv1.sys
[2015/08/28 18:17:54 | 000,925,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Unistore.dll
[2015/08/28 18:17:54 | 000,869,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapControlCore.dll
[2015/08/28 18:17:54 | 000,858,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2015/08/28 18:17:54 | 000,856,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ContactApis.dll
[2015/08/28 18:17:54 | 000,832,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapsStore.dll
[2015/08/28 18:17:54 | 000,783,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2015/08/28 18:17:54 | 000,752,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\efscore.dll
[2015/08/28 18:17:54 | 000,695,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimgapi.dll
[2015/08/28 18:17:54 | 000,654,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PlayToManager.dll
[2015/08/28 18:17:54 | 000,632,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2015/08/28 18:17:54 | 000,630,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2015/08/28 18:17:54 | 000,623,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ContactApis.dll
[2015/08/28 18:17:54 | 000,578,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winlogon.exe
[2015/08/28 18:17:54 | 000,521,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wimserv.exe
[2015/08/28 18:17:54 | 000,505,344 | ---- | M] () -- C:\WINDOWS\SysNative\EditionUpgradeManagerObj.dll
[2015/08/28 18:17:54 | 000,494,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StoreAgent.dll
[2015/08/28 18:17:54 | 000,446,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MapConfiguration.dll
[2015/08/28 18:17:54 | 000,430,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcomapi.dll
[2015/08/28 18:17:54 | 000,425,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2015/08/28 18:17:54 | 000,416,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2015/08/28 18:17:54 | 000,366,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuuhext.dll
[2015/08/28 18:17:54 | 000,359,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncsi.dll
[2015/08/28 18:17:54 | 000,343,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\usocore.dll
[2015/08/28 18:17:54 | 000,342,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcastdvr.exe
[2015/08/28 18:17:54 | 000,329,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusUpdateHandlers.dll
[2015/08/28 18:17:54 | 000,328,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MapConfiguration.dll
[2015/08/28 18:17:54 | 000,303,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MBMediaManager.dll
[2015/08/28 18:17:54 | 000,290,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wininit.exe
[2015/08/28 18:17:54 | 000,287,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provhandlers.dll
[2015/08/28 18:17:54 | 000,268,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provengine.dll
[2015/08/28 18:17:54 | 000,242,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\updatehandlers.dll
[2015/08/28 18:17:54 | 000,229,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorService.dll
[2015/08/28 18:17:54 | 000,208,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2015/08/28 18:17:54 | 000,208,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\srumsvc.dll
[2015/08/28 18:17:54 | 000,204,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmcsp.dll
[2015/08/28 18:17:54 | 000,204,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OmaDmAgent.dll
[2015/08/28 18:17:54 | 000,190,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReInfo.dll
[2015/08/28 18:17:54 | 000,187,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\provisioningcsp.dll
[2015/08/28 18:17:54 | 000,186,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BootMenuUX.dll
[2015/08/28 18:17:54 | 000,185,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\psmsrv.dll
[2015/08/28 18:17:54 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdboot.exe
[2015/08/28 18:17:54 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storewuauth.dll
[2015/08/28 18:17:54 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotification.exe
[2015/08/28 18:17:54 | 000,144,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UMDF\SensorsCx.dll
[2015/08/28 18:17:54 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VEStoreEventHandlers.dll
[2015/08/28 18:17:54 | 000,120,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\omadmclient.exe
[2015/08/28 18:17:54 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SensorsNativeApi.V2.dll
[2015/08/28 18:17:54 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\spbcd.dll
[2015/08/28 18:17:54 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2015/08/28 18:17:54 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SensorsNativeApi.V2.dll
[2015/08/28 18:17:54 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\setbcdlocale.dll
[2015/08/28 18:17:54 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\unenrollhook.dll
[2015/08/28 18:17:54 | 000,061,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dam.sys
[2015/08/28 18:17:54 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hmkd.dll
[2015/08/28 18:17:54 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotificationUx.exe
[2015/08/28 18:17:54 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\omadmprc.exe
[2015/08/28 18:17:54 | 000,045,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\hmkd.dll
[2015/08/28 18:17:54 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\VoiceActivationManager.dll
[2015/08/28 18:17:54 | 000,032,768 | ---- | M] () -- C:\WINDOWS\SysNative\LicenseManagerApi.dll
[2015/08/28 18:17:54 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicenseManagerShellext.exe
[2015/08/28 18:17:53 | 006,488,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\windows.storage.dll
[2015/08/28 18:17:53 | 004,611,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2015/08/28 18:17:53 | 003,248,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msftedit.dll
[2015/08/28 18:17:53 | 002,606,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msftedit.dll
[2015/08/28 18:17:53 | 002,125,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.appcore.dll
[2015/08/28 18:17:53 | 001,714,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.appcore.dll
[2015/08/28 18:17:53 | 001,203,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Bluetooth.dll
[2015/08/28 18:17:53 | 001,101,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2015/08/28 18:17:53 | 000,966,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinapi.appcore.dll
[2015/08/28 18:17:53 | 000,841,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Import.dll
[2015/08/28 18:17:53 | 000,828,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Bluetooth.dll
[2015/08/28 18:17:53 | 000,823,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2015/08/28 18:17:53 | 000,808,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CoreMessaging.dll
[2015/08/28 18:17:53 | 000,762,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinapi.appcore.dll
[2015/08/28 18:17:53 | 000,680,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Networking.Connectivity.dll
[2015/08/28 18:17:53 | 000,679,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppContracts.dll
[2015/08/28 18:17:53 | 000,677,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2015/08/28 18:17:53 | 000,658,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipSVC.dll
[2015/08/28 18:17:53 | 000,590,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MessagingDataModel2.dll
[2015/08/28 18:17:53 | 000,575,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Import.dll
[2015/08/28 18:17:53 | 000,518,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationController.dll
[2015/08/28 18:17:53 | 000,510,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CoreMessaging.dll
[2015/08/28 18:17:53 | 000,503,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Networking.Connectivity.dll
[2015/08/28 18:17:53 | 000,465,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MessagingDataModel2.dll
[2015/08/28 18:17:53 | 000,441,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppContracts.dll
[2015/08/28 18:17:53 | 000,421,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Bluetooth.dll
[2015/08/28 18:17:53 | 000,335,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wintrust.dll
[2015/08/28 18:17:53 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Internal.Bluetooth.dll
[2015/08/28 18:17:53 | 000,263,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DisplayManager.dll
[2015/08/28 18:17:53 | 000,191,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DisplayManager.dll
[2015/08/28 18:17:53 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmapi.dll
[2015/08/28 18:17:53 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ACPBackgroundManagerPolicy.dll
[2015/08/28 18:17:53 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbser.sys
[2015/08/28 18:17:53 | 000,065,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\bthhfenum.sys
[2015/08/28 18:17:53 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UcmUcsi.sys
[2015/08/28 18:17:53 | 000,037,376 | ---- | M] (Adobe Systems) -- C:\WINDOWS\SysWow64\atmlib.dll
[2015/08/28 18:17:53 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\VoiceActivationManager.dll
[2015/08/28 18:17:53 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationControllerPS.dll
[2015/08/28 18:13:02 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa.tlb
[2015/08/28 18:13:02 | 000,091,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa30.tlb
[2015/08/28 18:13:02 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa20.tlb
[2015/08/28 18:13:02 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa10.tlb
[2015/08/28 18:13:00 | 000,635,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqsnap.dll
[2015/08/28 18:13:00 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqcertui.dll
[2015/08/28 18:12:58 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iisRtl.dll
[2015/08/28 18:12:58 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\admwprox.dll
[2015/08/28 18:12:57 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ahadmin.dll
[2015/08/28 18:12:57 | 000,018,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iisreset.exe
[2015/08/28 18:12:57 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wamregps.dll
[2015/08/28 18:12:57 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iisrstap.dll
[2015/08/28 18:12:56 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\mqac.sys
[2015/08/28 18:12:55 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iisRtl.dll
[2015/08/28 18:12:55 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\admwprox.dll
[2015/08/28 18:12:54 | 000,229,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqrt.dll
[2015/08/28 18:12:54 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ahadmin.dll
[2015/08/28 18:12:54 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iisreset.exe
[2015/08/28 18:12:54 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wamregps.dll
[2015/08/28 18:12:54 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iisrstap.dll
[2015/08/28 18:12:52 | 000,265,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqoa.dll
[2015/08/28 18:12:52 | 000,009,096 | ---- | M] () -- C:\WINDOWS\SysWow64\msmqtrc.mof
[2015/08/28 18:12:51 | 000,130,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqlogmgr.dll
[2015/08/28 18:12:50 | 000,564,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqutil.dll
[2015/08/28 18:12:48 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa.tlb
[2015/08/28 18:12:48 | 000,091,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa30.tlb
[2015/08/28 18:12:48 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa20.tlb
[2015/08/28 18:12:48 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa10.tlb
[2015/08/28 18:12:46 | 000,813,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqsnap.dll
[2015/08/28 18:12:46 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqcertui.dll
[2015/08/28 18:12:45 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqoa.dll
[2015/08/28 18:12:45 | 000,009,096 | ---- | M] () -- C:\WINDOWS\SysNative\msmqtrc.mof
[2015/08/28 18:12:44 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqrt.dll
[2015/08/28 18:12:43 | 001,417,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqqm.dll
[2015/08/28 18:12:41 | 000,562,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mqutil.dll
[2015/08/28 18:12:39 | 000,052,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqbkup.exe
[2015/08/28 18:12:39 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mqsvc.exe
[2015/08/28 18:02:53 | 000,018,736 | -H-- | M] () -- C:\WINDOWS\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015/08/28 18:02:53 | 000,018,736 | -H-- | M] () -- C:\WINDOWS\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015/08/28 18:01:33 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2015/08/28 12:33:09 | 000,000,035 | ---- | M] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2015/08/28 02:17:24 | 000,097,888 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
  • ぐぬぬ
  • 2015/09/09 (Wed) 20:12:14
Re: DNSUnlockerの広告等々・・・
OTL 4/4

[2015/08/27 03:33:05 | 000,007,607 | ---- | M] () -- C:\Users\【ユーザー名】\AppData\Local\Resmon.ResmonCfg
[2015/08/26 23:19:20 | 000,001,172 | ---- | M] () -- C:\Users\Public\Desktop\Intel(R) Driver Update Utility 2.2.lnk
[2015/08/26 23:18:58 | 005,069,632 | ---- | M] (Intel) -- C:\Users\【ユーザー名】\Desktop\Intel Driver Update Utility Installer.exe
[2015/08/20 15:07:55 | 008,019,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2015/08/20 15:06:53 | 000,609,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2015/08/20 14:57:13 | 000,077,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2015/08/20 14:26:23 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InstallAgent.exe
[2015/08/20 14:21:28 | 021,875,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2015/08/20 14:21:13 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EnterpriseModernAppMgmtCSP.dll
[2015/08/20 13:31:28 | 018,806,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2015/08/18 16:56:25 | 002,498,808 | ---- | M] () -- C:\WINDOWS\SysNative\CoreUIComponents.dll
[2015/08/18 16:55:45 | 000,373,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2015/08/18 16:54:30 | 001,396,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicenseManager.dll
[2015/08/18 16:27:23 | 001,771,592 | ---- | M] () -- C:\WINDOWS\SysWow64\CoreUIComponents.dll
[2015/08/18 16:24:35 | 000,963,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LicenseManager.dll
[2015/08/18 16:13:10 | 000,497,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WlanMediaManager.dll
[2015/08/18 16:13:06 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetSetupShim.dll
[2015/08/18 16:12:20 | 000,692,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\UMDF\NfcCx.dll
[2015/08/18 16:12:18 | 002,225,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetworkMobileSettings.dll
[2015/08/18 16:04:20 | 000,859,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\modernexecserver.dll
[2015/08/18 16:04:14 | 001,234,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aitstatic.exe
[2015/08/18 15:59:35 | 001,294,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcnwiz.dll
[2015/08/18 15:59:02 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnApi.dll
[2015/08/18 15:58:46 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WcnNetsh.dll
[2015/08/18 15:58:34 | 000,112,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fdWCN.dll
[2015/08/18 15:58:31 | 000,117,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dafWCN.dll
[2015/08/18 15:58:25 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NetSetupSvc.dll
[2015/08/18 15:57:54 | 000,045,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wfdprov.dll
[2015/08/18 15:56:48 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BthRadioMedia.dll
[2015/08/18 15:55:01 | 002,178,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2015/08/18 15:54:11 | 000,247,296 | ---- | M] () -- C:\WINDOWS\SysNative\facecredentialprovider.dll
[2015/08/18 15:54:03 | 000,322,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vaultsvc.dll
[2015/08/18 15:52:26 | 001,888,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2015/08/18 15:50:04 | 001,795,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.dll
[2015/08/18 15:49:52 | 001,061,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\reseteng.dll
[2015/08/18 15:49:20 | 000,246,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PackageStateRoaming.dll
[2015/08/18 15:49:03 | 000,274,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\NetSetupShim.dll
[2015/08/18 15:36:08 | 001,226,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wcnwiz.dll
[2015/08/18 15:35:49 | 000,100,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WcnApi.dll
[2015/08/18 15:34:44 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wfdprov.dll
[2015/08/18 15:29:11 | 001,593,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2015/08/18 15:26:08 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PackageStateRoaming.dll
[2015/08/18 13:44:12 | 000,008,847 | ---- | M] () -- C:\WINDOWS\SysNative\ResPriHMImageList
[2015/08/16 23:03:02 | 000,000,571 | ---- | M] () -- C:\Users\【ユーザー名】\Desktop\あすなな.lnk
[2015/08/13 13:22:26 | 002,093,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlidsvc.dll
[2015/08/13 13:20:39 | 000,414,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2015/08/13 12:53:21 | 000,311,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2015/08/11 19:04:24 | 002,462,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2015/08/11 19:04:23 | 004,532,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2015/08/11 19:04:15 | 001,087,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfplat.dll
[2015/08/11 19:03:09 | 000,442,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\storport.sys
[2015/08/11 19:02:57 | 000,554,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\directmanipulation.dll
[2015/08/11 19:02:56 | 000,080,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\stornvme.sys
[2015/08/11 19:02:49 | 000,292,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockAppHost.exe
[2015/08/11 18:52:49 | 000,993,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ReAgent.dll
[2015/08/11 18:50:47 | 001,643,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diagtrack.dll
[2015/08/11 18:40:22 | 004,048,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2015/08/11 18:40:12 | 000,918,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfplat.dll
[2015/08/11 18:40:08 | 002,151,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2015/08/11 18:38:22 | 000,454,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\directmanipulation.dll
[2015/08/11 18:37:48 | 000,243,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LockAppHost.exe
[2015/08/11 18:26:03 | 000,845,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReAgent.dll
[2015/08/11 18:23:59 | 016,706,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2015/08/11 18:21:13 | 000,148,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tetheringservice.dll
[2015/08/11 18:21:04 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tetheringclient.dll
[2015/08/11 18:20:02 | 000,483,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\OneDriveSettingSyncProvider.dll
[2015/08/11 18:19:45 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Notifications.dll
[2015/08/11 18:18:44 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserMgrProxy.dll
[2015/08/11 18:16:32 | 002,416,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MFMediaEngine.dll
[2015/08/11 18:14:02 | 000,404,480 | ---- | M] () -- C:\WINDOWS\SysNative\diagtrack_wininternal.dll
[2015/08/11 18:13:42 | 000,413,184 | ---- | M] () -- C:\WINDOWS\SysNative\diagtrack_win.dll
[2015/08/11 18:11:40 | 002,446,336 | ---- | M] () -- C:\WINDOWS\SysNative\InputService.dll
[2015/08/11 18:11:18 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GamePanel.exe
[2015/08/11 18:10:47 | 000,293,376 | ---- | M] () -- C:\WINDOWS\SysNative\TextInputFramework.dll
[2015/08/11 18:10:12 | 000,324,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/08/11 18:10:06 | 000,778,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.dll
[2015/08/11 18:09:55 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuautoappupdate.dll
[2015/08/11 18:08:04 | 000,893,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApiPublic.dll
[2015/08/11 18:08:04 | 000,563,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeApi.dll
[2015/08/11 18:07:52 | 000,593,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wcmsvc.dll
[2015/08/11 18:07:44 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MbaeParserTask.exe
[2015/08/11 18:06:19 | 007,523,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2015/08/11 18:05:48 | 000,342,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationGeofences.dll
[2015/08/11 18:05:27 | 000,269,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationFramework.dll
[2015/08/11 18:05:23 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationFrameworkInternalPS.dll
[2015/08/11 18:05:20 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationPermissions.dll
[2015/08/11 18:05:10 | 000,996,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RDXService.dll
[2015/08/11 18:05:07 | 003,527,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tquery.dll
[2015/08/11 18:03:09 | 002,558,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssrch.dll
[2015/08/11 18:02:53 | 000,186,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cloudAP.dll
[2015/08/11 18:02:15 | 000,621,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enterprisecsps.dll
[2015/08/11 18:02:08 | 003,588,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2015/08/11 18:01:38 | 001,334,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIAutomationCore.dll
[2015/08/11 18:00:45 | 000,336,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchProtocolHost.exe
[2015/08/11 18:00:06 | 000,274,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\syncutil.dll
[2015/08/11 17:59:51 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssprxy.dll
[2015/08/11 17:59:33 | 000,042,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tetheringclient.dll
[2015/08/11 17:59:27 | 000,642,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdbui.dll
[2015/08/11 17:58:11 | 000,372,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\OneDriveSettingSyncProvider.dll
[2015/08/11 17:57:51 | 013,024,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2015/08/11 17:57:12 | 000,159,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserMgrProxy.dll
[2015/08/11 17:51:35 | 001,916,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MFMediaEngine.dll
[2015/08/11 17:51:33 | 001,823,232 | ---- | M] () -- C:\WINDOWS\SysWow64\InputService.dll
[2015/08/11 17:50:59 | 000,131,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Core.TextInput.dll
[2015/08/11 17:50:58 | 000,200,704 | ---- | M] () -- C:\WINDOWS\SysWow64\TextInputFramework.dll
[2015/08/11 17:50:47 | 000,420,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GamePanel.exe
[2015/08/11 17:49:50 | 000,586,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.dll
[2015/08/11 17:49:30 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/08/11 17:48:25 | 000,671,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApiPublic.dll
[2015/08/11 17:47:09 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MbaeApi.dll
[2015/08/11 17:43:39 | 002,748,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tquery.dll
[2015/08/11 17:42:33 | 005,454,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2015/08/11 17:40:32 | 001,964,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssrch.dll
[2015/08/11 17:40:12 | 001,112,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIAutomationCore.dll
[2015/08/11 17:38:43 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ReInfo.dll

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2015/09/09 19:33:50 | 000,016,148 | ---- | C] () -- C:\WINDOWS\SysNative\【ユーザー名】-PC_【ユーザー名】_HistoryPrediction.bin
[2015/09/07 20:17:37 | 005,858,092 | ---- | C] () -- C:\Users\【ユーザー名】\%userprofile
[2015/09/02 21:57:04 | 000,000,214 | ---- | C] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2015/09/02 21:46:05 | 000,002,457 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
[2015/09/02 21:46:05 | 000,002,126 | ---- | C] () -- C:\Users\Public\Desktop\Acrobat Reader DC.lnk
[2015/09/01 23:59:27 | 000,000,865 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015/08/31 16:11:33 | 000,000,085 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2015/08/29 15:48:34 | 002,498,808 | ---- | C] () -- C:\WINDOWS\SysNative\CoreUIComponents.dll
[2015/08/29 15:48:33 | 001,771,592 | ---- | C] () -- C:\WINDOWS\SysWow64\CoreUIComponents.dll
[2015/08/29 15:48:30 | 000,247,296 | ---- | C] () -- C:\WINDOWS\SysNative\facecredentialprovider.dll
[2015/08/29 15:48:30 | 000,008,847 | ---- | C] () -- C:\WINDOWS\SysNative\ResPriHMImageList
[2015/08/28 22:32:06 | 002,446,336 | ---- | C] () -- C:\WINDOWS\SysNative\InputService.dll
[2015/08/28 22:32:00 | 001,823,232 | ---- | C] () -- C:\WINDOWS\SysWow64\InputService.dll
[2015/08/28 22:31:59 | 000,404,480 | ---- | C] () -- C:\WINDOWS\SysNative\diagtrack_wininternal.dll
[2015/08/28 22:31:58 | 000,413,184 | ---- | C] () -- C:\WINDOWS\SysNative\diagtrack_win.dll
[2015/08/28 22:31:56 | 000,293,376 | ---- | C] () -- C:\WINDOWS\SysNative\TextInputFramework.dll
[2015/08/28 22:31:52 | 000,200,704 | ---- | C] () -- C:\WINDOWS\SysWow64\TextInputFramework.dll
[2015/08/28 20:08:40 | 000,002,271 | ---- | C] () -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
[2015/08/28 20:06:45 | 000,001,926 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0xf0.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x21.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x11.dfu
[2015/08/28 20:06:45 | 000,001,926 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40.dfu
[2015/08/28 20:06:45 | 000,001,922 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010100_40.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40_SS01.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40_nf01.dfu
[2015/08/28 20:06:45 | 000,001,802 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020100_40.dfu
[2015/08/28 20:06:45 | 000,001,796 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x11020000_40.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_SS01.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_LV01.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0xf1.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x22.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x12.dfu
[2015/08/28 20:06:45 | 000,001,516 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010000_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,512 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x31010100_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,242 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2015/08/28 20:06:45 | 000,001,228 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x04.dfu
[2015/08/28 20:06:45 | 000,001,214 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x03.dfu
[2015/08/28 20:06:45 | 000,001,204 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2015/08/28 20:06:45 | 000,001,204 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_40.dfu
[2015/08/28 20:06:45 | 000,001,198 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26.dfu
[2015/08/28 20:06:45 | 000,001,192 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020200_26_0x01.dfu
[2015/08/28 20:06:45 | 000,000,296 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x01.dfu
[2015/08/28 20:06:45 | 000,000,278 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x04.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x03.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40_0x02.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_40.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26_0x01.dfu
[2015/08/28 20:06:45 | 000,000,264 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\ramps_0x01020201_26.dfu
[2015/08/28 20:06:44 | 000,246,804 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AtherosBT.bin
[2015/08/28 20:06:44 | 000,048,092 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020200.dfu
[2015/08/28 20:06:44 | 000,046,748 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010000.dfu
[2015/08/28 20:06:44 | 000,046,268 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020100.dfu
[2015/08/28 20:06:44 | 000,046,212 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x11020000.dfu
[2015/08/28 20:06:44 | 000,040,684 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010000_ss01.dfu
[2015/08/28 20:06:44 | 000,038,140 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x31010100.dfu
[2015/08/28 20:06:44 | 000,023,532 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\AthrBT_0x01020201.dfu
[2015/08/28 19:00:28 | 000,023,208 | ---- | C] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2015/08/28 18:48:21 | 000,001,576 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2015/08/28 18:34:27 | 000,000,352 | ---- | C] () -- C:\Users\【ユーザー名】\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2015/08/28 18:34:27 | 000,000,334 | ---- | C] () -- C:\Users\【ユーザー名】\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2015/08/28 18:33:12 | 001,926,530 | ---- | C] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2015/08/28 18:33:07 | 001,667,602 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2015/08/28 18:31:12 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01011.Wdf
[2015/08/28 18:30:46 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
[2015/08/28 18:26:01 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys
[2015/08/28 18:17:54 | 000,505,344 | ---- | C] () -- C:\WINDOWS\SysNative\EditionUpgradeManagerObj.dll
[2015/08/28 18:17:54 | 000,032,768 | ---- | C] () -- C:\WINDOWS\SysNative\LicenseManagerApi.dll
[2015/08/28 18:01:29 | 000,000,001 | -HS- | C] () -- C:\BOOTNXT
[2015/08/28 17:53:31 | 000,010,449 | ---- | C] () -- C:\WINDOWS\diagerr.xml
[2015/08/28 17:53:31 | 000,009,528 | ---- | C] () -- C:\WINDOWS\diagwrn.xml
[2015/08/26 23:19:20 | 000,001,172 | ---- | C] () -- C:\Users\Public\Desktop\Intel(R) Driver Update Utility 2.2.lnk
[2015/08/24 03:14:49 | 000,007,607 | ---- | C] () -- C:\Users\【ユーザー名】\AppData\Local\Resmon.ResmonCfg
[2015/08/16 23:03:02 | 000,000,571 | ---- | C] () -- C:\Users\【ユーザー名】\Desktop\あすなな.lnk
[2015/07/10 21:20:52 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2015/07/10 20:04:39 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2015/07/10 20:04:38 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2015/07/10 20:00:35 | 000,161,632 | ---- | C] () -- C:\WINDOWS\SysWow64\weretw.dll
[2015/07/10 20:00:33 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
[2015/07/10 20:00:32 | 000,047,104 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2015/07/10 20:00:31 | 000,156,672 | ---- | C] () -- C:\WINDOWS\SysWow64\MTF.dll
[2015/07/10 20:00:30 | 000,028,672 | ---- | C] () -- C:\WINDOWS\SysWow64\dtdump.exe
[2015/07/10 20:00:29 | 000,081,408 | ---- | C] () -- C:\WINDOWS\SysWow64\InputLocaleManager.dll
[2015/07/10 20:00:29 | 000,057,344 | ---- | C] () -- C:\WINDOWS\SysWow64\EditBufferTestHook.dll
[2015/07/10 20:00:29 | 000,053,760 | ---- | C] () -- C:\WINDOWS\SysWow64\WpKbdLayout.dll
[2015/07/10 20:00:29 | 000,022,016 | ---- | C] () -- C:\WINDOWS\SysWow64\WordBreakers.dll
[2015/07/10 20:00:28 | 000,270,848 | ---- | C] () -- C:\WINDOWS\SysWow64\HrtfApo.dll
[2015/07/10 20:00:27 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2015/07/10 20:00:26 | 000,022,528 | ---- | C] () -- C:\WINDOWS\SysWow64\efsext.dll
[2015/07/10 20:00:25 | 000,002,269 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2015/07/10 20:00:24 | 000,167,640 | ---- | C] () -- C:\WINDOWS\SysWow64\chs_singlechar_pinyin.dat
[2015/07/10 19:59:51 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2015/06/01 21:00:18 | 000,090,112 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll
[2015/06/01 19:46:58 | 000,272,928 | ---- | C] () -- C:\WINDOWS\SysWow64\igvpkrng600.bin
[2015/06/01 19:45:24 | 000,963,452 | ---- | C] () -- C:\WINDOWS\SysWow64\igcodeckrng600.bin
[2014/10/20 15:53:32 | 000,000,994 | ---- | C] () -- C:\Users\【ユーザー名】\.recently-used.xbel

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2015/09/06 13:25:30 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\windows.storage.dll -- [2015/08/28 18:17:53 | 006,488,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\windows.storage.dll -- [2015/08/28 18:17:54 | 005,118,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2015/07/10 19:59:53 | 000,995,328 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2015/07/10 20:00:23 | 000,754,688 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2015/07/10 19:59:55 | 000,516,096 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Custom Scans ==========[/color]
[2012/05/30 14:11:23 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2015/09/08 22:01:34 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2015/08/29 03:07:20 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2012/04/17 10:54:47 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\CSharp
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\csharp-shared
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\MCpp
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\VBasic
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\vbasic-shared
[2012/05/30 14:54:59 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\VCATL
[2012/05/30 14:54:55 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\Extensibility Projects\vcatl-shared
[2015/09/09 18:18:15 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsApps
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ
[2015/08/24 17:24:39 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ\IJPrinter
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ\IJPrinter\CNMWindows
[2013/04/08 13:41:08 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ\IJPrinter\CNMWindows\Canon MP980 series Printer
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc
[2015/07/10 21:21:42 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2015/07/11 01:34:34 | 000,000,000 | RH-D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\DMProfiles
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\ProgramData\Microsoft\WwanSvc\Profiles
[2015/08/28 19:01:56 | 000,000,000 | RH-D | M] -- C:\Users\Default
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonBJ
[2015/08/24 17:24:39 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Common Files
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonBJ\IJPrinter
[2013/04/08 13:39:26 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonBJ\IJPrinter\CNMWindows
[2013/04/08 13:41:08 | 000,000,000 | -H-D | M] -- C:\Users\All Users\CanonBJ\IJPrinter\CNMWindows\Canon MP980 series Printer
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc
[2015/07/10 21:21:42 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\Windows\DeviceMetadataCache\dmrccache\downloads
[2015/07/11 01:34:34 | 000,000,000 | RH-D | M] -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Tablet PC
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\DMProfiles
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\Users\All Users\Microsoft\WwanSvc\Profiles
[2015/07/10 20:04:22 | 000,000,000 | -H-D | M] -- C:\Users\Default\AppData
[2015/08/31 16:16:07 | 000,000,000 | RH-D | M] -- C:\Users\Public\AccountPictures
[2015/09/04 19:30:27 | 000,000,000 | RH-D | M] -- C:\Users\Public\Desktop
[2009/07/14 11:34:59 | 000,000,000 | RH-D | M] -- C:\Users\Public\Favorites
[2015/08/28 19:00:10 | 000,000,000 | RH-D | M] -- C:\Users\Public\Libraries
[2015/08/28 18:36:06 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData
[2015/08/28 20:08:18 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~
[2012/05/30 00:26:41 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~
[2015/09/08 20:55:15 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\Windows\INetCache\Virtualized
[2015/08/28 20:03:10 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\Microsoft\Windows\INetCookies\PrivacIE\Low
[2015/01/22 15:35:30 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Local\VirtualStore\ProgramData
[2015/08/28 18:57:16 | 000,000,000 | -H-D | M] -- C:\Users\【ユーザー名】\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2015/07/10 20:04:27 | 000,000,000 | -H-D | M] -- C:\Windows\ELAMBKUP
[2015/08/28 18:42:27 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\LocalService\AppData
[2015/08/28 22:48:34 | 000,000,000 | -H-D | M] -- C:\Windows\ServiceProfiles\NetworkService\AppData
[2015/08/28 18:36:39 | 000,000,000 | -H-D | M] -- C:\WINDOWS\SysNative\GroupPolicy

[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2015/09/09 19:07:00 | 000,000,626 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2015/09/08 22:50:42 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2015/09/09 15:16:58 | 000,000,710 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2015/09/09 19:08:00 | 000,000,714 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[color=#E56717]========== Drive Information ==========[/color]

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: Hitachi HTS547575A9E384
Partitions: 3
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 25.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 279.00GB
Starting Offset: 26844594176
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 394.00GB
Starting Offset: 326906150912
Hidden sectors: 0


[color=#E56717]========== Base Services ==========[/color]
No service found with a name of AeLookupSvc
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,093,696 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,097,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 001,168,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,794,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,096,256 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV - [2015/07/10 20:00:27 | 000,069,632 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,472,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2015/07/10 20:00:26 | 000,344,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:39 | 000,133,120 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,077,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,873,984 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,356,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2015/07/10 20:00:30 | 000,292,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:09 | 000,276,992 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:52 | 000,106,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (Eaphost)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,034,304 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2015/07/10 20:00:26 | 000,029,696 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,452,608 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:52 | 000,390,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:[b]64bit:[/b] - [2015/07/10 19:59:55 | 000,464,896 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
No service found with a name of MMCSS
SRV:[b]64bit:[/b] - [2015/07/10 19:59:53 | 000,265,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,550,400 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:09 | 000,371,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,029,184 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:57 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:14 | 000,781,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
No service found with a name of ProtectedStorage
No service found with a name of EMDMgmt
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,106,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:51 | 000,679,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:59 | 000,873,984 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:10 | 000,056,344 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:09 | 000,179,200 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,283,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:19 | 000,593,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2015/07/10 20:00:33 | 000,544,768 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:[b]64bit:[/b] - [2015/08/03 10:22:29 | 001,008,640 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:14 | 000,311,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2015/07/10 20:00:32 | 000,254,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:17 | 000,058,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:02 | 000,324,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:58 | 001,370,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:58 | 001,067,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (Audiosrv)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:58 | 000,280,064 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:09 | 000,150,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:48 | 000,024,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:54 | 001,729,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (EventLog)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:07 | 000,856,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:01:10 | 000,637,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:[b]64bit:[/b] - [2015/08/28 18:17:54 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\msiexec.exe -- (msiserver)
SRV - [2015/08/28 18:17:57 | 000,058,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysWow64\msiexec.exe -- (msiserver)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:[b]64bit:[/b] - [2015/08/20 14:13:54 | 002,235,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:[b]64bit:[/b] - [2015/07/10 19:59:50 | 000,263,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:[b]64bit:[/b] - [2015/08/18 16:07:34 | 002,226,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (WlanSvc)
SRV:[b]64bit:[/b] - [2015/07/10 20:00:01 | 000,279,040 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

< End of report >
  • ぐぬぬ
  • 2015/09/09 (Wed) 20:13:16
Re: DNSUnlockerの広告等々・・・
Extras

OTL Extras logfile created on: 2015/09/04 20:08:22 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\【ユーザー名】\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.10240.16384)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

7.91 Gb Total Physical Memory | 5.97 Gb Available Physical Memory | 75.41% Memory free
15.91 Gb Paging File | 14.01 Gb Available in Paging File | 88.07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.45 Gb Total Space | 211.00 Gb Free Space | 75.50% Space Free | Partition Type: NTFS
Drive D: | 394.18 Gb Total Space | 393.85 Gb Free Space | 99.92% Space Free | Partition Type: NTFS

Computer Name: 【ユーザー名】-PC | User Name: 【ユーザー名】 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3922431837-200563891-1274897566-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = EF EB 54 8B 78 E1 D0 01 [binary data]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = A7 74 5E 8B 78 E1 D0 01 [binary data]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{76AA7345-9C0C-4120-9466-C2FDE56D431D}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{A285F19E-0391-45DA-ADAD-CA76B8D275D8}" = lport=4588 | protocol=6 | dir=in | app=c:\windows\syswow64\config\systemprofile\appdata\local\windows internet name service\wins.exe |
"{A2A9038D-9E61-4895-BECE-69CB8DD424A2}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{AF476326-0765-4093-BA93-24AB3654A843}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B0052AB6-FEB8-4ECD-B4AD-286048092ED0}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B36EC7EF-8809-4BED-82B4-F3C0DCD5DD2E}" = lport=4588 | protocol=17 | dir=in | app=c:\windows\syswow64\config\systemprofile\appdata\local\windows internet name service\wins.exe |
"{BE63DC2A-9A55-4D85-9816-E8FA7B68C34C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{D9C54D23-CDC7-446F-9F7B-E9FB14FE76C3}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01A08150-3650-40C9-9C68-FE9E8870DF65}" = dir=out | name=@{microsoft.appconnector_1.3.3.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.appconnector/resources/connectorstubtitle} |
"{024C1651-1E4E-4995-A4E8-3CDEC95AB115}" = dir=out | name=candy crush saga |
"{0420B7F2-1900-4F5F-A9A2-FF428661DE38}" = dir=out | name=@{microsoft.windows.cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} |
"{048ACAEE-9E2C-4F68-ACFD-8DF57D1D0EA4}" = dir=in | name=@{microsoft.bingweather_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} |
"{05BD945B-5851-4454-9C06-28F19BB84D51}" = dir=out | name=@{microsoft.lockapp_10.0.10240.16384_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{08E2AD17-626B-4300-B19D-EC3F6186A984}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{0B65E9B1-F492-43FF-8574-4079597F135E}" = dir=out | name=@{windows.contactsupport_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{14A7006E-84CC-427C-B167-8C674BF1A246}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{1782C34A-6693-4C1B-9E00-636D0148DFF4}" = dir=out | name=@{microsoft.bingnews_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} |
"{1C9402F3-EE6B-4551-9209-B4E4D37CEB3E}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} |
"{23D7E189-14A1-4012-834D-75F2CEA6F16B}" = dir=out | name=@{microsoft.bingsports_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} |
"{37F6997D-6416-486C-83F5-ED1CCB98F302}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.6121.42001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/appmanifest_outlookdesktop_displayname} |
"{387B5133-C741-40C2-8F3A-4797C3555EC7}" = dir=in | name=@{microsoft.bingnews_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} |
"{3D43F6DC-B7A3-45C7-8142-C02C9B9FF887}" = dir=in | name=@{microsoft.microsoftedge_20.10240.16384.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{41D207C8-98B9-4CCC-9BE9-BB01043676D1}" = dir=out | name=@{microsoft.bingfinance_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} |
"{46F3C9B3-A2C5-420E-879D-BD41C09A9EC1}" = dir=in | name=microsoft solitaire collection |
"{49EA16CD-4131-4C2D-877C-43069627103A}" = dir=out | name=microsoft solitaire collection |
"{4ADF2CB4-E84B-406C-9CA8-27E0D247D82B}" = dir=out | name=@{microsoft.xboxidentityprovider_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxidentityprovider/resources/pkgdisplayname} |
"{4AEC336B-2FC0-46BA-A428-78720500DE69}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{50D1D736-D8D0-4CCB-AAFE-DD76182D5990}" = dir=out | app=c:\windows\syswow64\config\systemprofile\appdata\local\windows internet name service\wins.exe |
"{5B07B081-3A86-4AA0-966F-E3874376B51A}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{611E2C49-1ABD-4623-8A08-FB5CE707E1AA}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} |
"{6B57533C-3565-4F3A-A9A5-FA09A0E12B22}" = dir=out | name=@{microsoft.windowsstore_2015.8.25.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} |
"{75021B4F-0AB5-4187-BC7B-B1D72705D027}" = dir=out | name=@{microsoft.people_1.10241.0.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.people/resources/appstorename} |
"{79AF7BA8-F8C3-4322-8070-97648D60371B}" = dir=in | name=xbox |
"{7C773E52-11FA-4E10-BE8C-D7D6F7F38812}" = dir=out | name=onenote |
"{7CEB8E30-B5CE-4B54-9C41-DC5160A5869F}" = dir=out | name=xbox |
"{7FA27206-9E4E-4C15-B1C4-1D249AF6CF51}" = dir=out | name=@{microsoft.accountscontrol_10.0.10240.16384_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} |
"{860C11BF-52A5-4C18-85CE-49CF9EE20D49}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{873E866F-A086-4F34-A901-5D9749C32944}" = dir=in | name=onenote |
"{87B1ACF4-78F4-4B21-ABB1-E7491E32847A}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{8FA1C735-FAA0-4259-9A32-365CFC3D437D}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{90F73B26-A738-4B53-AA39-1018E2795BA6}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{96A6C57A-22F9-4408-8294-516785961995}" = dir=out | name=@{microsoft.windowsmaps_4.1507.50821.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsmaps/resources/appstorename} |
"{989145A7-7601-4D14-A21B-05991D4C61CE}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{AAD18B19-3E54-480C-95BA-5D2818FA3C27}" = dir=out | name=@{microsoft.windowsfeedback_10.0.10240.16393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windowsfeedback/feedbackapp.resources/appname/text} |
"{ACBCF777-199F-45EE-835B-79E6FF1E23D0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{B34C2383-3D7E-422D-B281-230DA69038D8}" = dir=out | name=@{microsoft.microsoftedge_20.10240.16384.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{B6F0DD56-C5B0-438A-976D-37D2BD93CF50}" = dir=out | name=@{microsoft.zunevideo_3.6.12711.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{BA4A7DA8-7697-4C3D-969D-D9525BF1223D}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{C1C34168-055B-4D77-9240-D2228C749AF7}" = dir=out | name=@{microsoft.windowsdvdplayer_3.6.11761.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsdvdplayer/resources/ids_dvdplayer_app_name} |
"{C1E1E3A9-8B60-4EC9-9699-7F989485B0FB}" = dir=in | name=@{microsoft.windowsstore_2015.8.25.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} |
"{C470B818-7B32-43D2-B56E-5978BB8800D4}" = dir=in | name=@{microsoft.windows.cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} |
"{C50307A9-B950-40ED-AC31-603BA9FE7075}" = dir=out | name=twitter |
"{C791AD11-F480-438F-BF97-573479593162}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.6121.42001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/appmanifest_outlookdesktop_displayname} |
"{D3BF01FA-5ADC-481F-8F6D-ED6F5A96A9E0}" = dir=out | name=@{microsoft.windowsphone_10.1508.17010.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphone/resources/appstorename} |
"{DA75C6AA-2E96-438A-AEDB-BBB40AE7AAE8}" = dir=out | name=@{microsoft.getstarted_2.3.4.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.getstarted/resources/appstorename} |
"{DBA2C57F-7029-49F5-A2C2-B21BB16D7667}" = dir=out | name=@{windows.purchasedialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.purchasedialog/resources/displayname} |
"{E2B7FD3A-4046-4C19-B1B0-C25A50549D1B}" = dir=in | name=@{microsoft.bingsports_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} |
"{E4D759F5-D3F9-4677-A580-F445FBD27508}" = dir=in | name=@{microsoft.bingfinance_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} |
"{E7BEB7B9-D48E-431C-992A-2D7F474B97FA}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{EEF661ED-8FCB-4224-9F31-09BAA674C60D}" = dir=in | name=@{windows.contactsupport_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{F09E0A8E-9530-44DF-8108-55C08720266A}" = dir=in | name=@{microsoft.microsoftofficehub_17.6121.23761.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} |
"{F637DEDD-E82F-4B96-9489-04335FDD3EB2}" = dir=out | name=windows_ie_ac_001 |
"{F6C7757E-E430-4290-8BCB-3F91A63977E9}" = dir=in | name=@{microsoft.windows.photos_15.827.16340.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} |
"{F735331E-926B-4B62-9693-F7479E532AA9}" = dir=out | name=@{microsoft.zunemusic_3.6.12711.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{F8340D5B-B333-4B63-9484-FC5F0975E0C8}" = dir=out | name=@{microsoft.3dbuilder_10.1.9.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.3dbuilder/resources/appstorename} |
"{F8A2AB89-82DA-4588-A798-C01438CF1423}" = dir=out | name=@{microsoft.microsoftofficehub_17.6121.23761.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} |
"{F92A7A2F-0074-48DF-9FA2-899A1DF74C35}" = dir=out | name=@{microsoft.bingweather_4.4.246.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} |
"{F998889C-B750-4B1D-A191-278EC416E8A3}" = dir=out | name=@{microsoft.windows.photos_15.827.16340.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0EE529F2-2742-494B-ACF5-2C68D82B8AFE}" = Windows Live Family Safety
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1AAF6669-31B2-3840-9346-F0F653840FD1}" = Microsoft .NET Framework 4.5.1 (JPN)
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{20752CA6-889D-4EBC-9392-929B4CFE3302}" = Microsoft SQL Server 2008 R2 管理オブジェクト (x64)
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
"{26784146-6E05-3FF9-9335-786C7C0FB5BE}" = Microsoft .NET Framework 4.5.2
"{2AAB9867-958C-4446-A66E-D5F52B736F99}" = Microsoft SQL Server 2008 Database Engine Shared
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{33B98264-A889-4913-A0CA-C364A75032B3}" = ASUS Power4Gear Hybrid
"{3AF674EE-1A2E-469B-88AC-E867CDB33D99}" = Microsoft SQL Server 2008 Native Client
"{3BF2C0A8-2C44-4A36-AA96-3BD6FB7BB01F}" = Windows Live Remote Client Resources
"{42407101-F6C1-3B67-AA7E-613FEC717081}" = Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319
"{4F5A98E0-2801-463C-8166-276FCB775980}" = Microsoft SQL Server System CLR Types (x64)
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{54C5B89F-0A8C-4C07-A51D-7380974DA459}" = Windows Live Remote Service Resources
"{5CA7FC9B-8508-4494-B365-6FBCBAEB8E89}" = Intel(R) Chipset Device Software
"{5DA6F56A-5E2D-4FB4-88CB-E9EE2B790A14}" = Microsoft SQL Server Compact 3.5 SP2 x64 JPN
"{616124A1-E9D8-3FC3-87E9-D906779F4765}" = Microsoft Team Foundation Server 2010 Object Model - JPN
"{61F2BDE9-816B-4BE6-AD63-0C349C2348CA}" = Microsoft Sync Framework Runtime v1.0 SP1 (x64) ja
"{761C6783-D3BC-48AB-8E7C-61CE918A8436}" = ASUS Secure Delete
"{8137177F-FA3A-4A90-B6A5-8CD066008EEF}" = Microsoft SQL Server VSS Writer
"{81455DEB-FC7E-3EE5-85CA-2EBDD9FD61EB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-0028-0411-1000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2010
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0411-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Japanese) 2010
"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{986E003C-E56D-5A47-110E-D3C81F0E8535}" = Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.11761.0_neutral_~_8wekyb3d8bbwe (x64)
"{A25A8788-0D02-4FC7-B7F7-C80DD7251FE3}" = Microsoft SQL Server 2008 Common Files
"{A2E3EA10-074E-4D8C-BDC8-69BFC7699ACE}" = Microsoft Sync Framework Services v1.0 SP1 (x64) ja
"{AC04591A-A74F-44C3-936A-D294C9D135C6}" = Microsoft SQL Server 2008 Database Engine Services
"{ADBD6E65-46CB-4A97-9AFB-64963FEACC40}" = Microsoft SQL Server 2008 RsFx Driver
"{B0E40F1B-713D-3F68-840C-23262E34BDB4}" = Microsoft Help Viewer 1.1 Language Pack - JPN
"{B41AFA7D-B721-4B6C-ACEA-4DC946F482B0}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) ja
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = インテル(R) ターボ・ブースト・テクノロジー・モニター 2.0
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{D2837730-4960-3B35-8088-201387FD3BDB}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - JPN
"{D57519D3-2E37-3E34-94AF-4D59BFAB87E6}" = Microsoft Visual Studio 2010 Office Developer Tools (x64)
"{D9FCBAAE-DB72-488B-96D0-0AA3C892C0D6}" = Microsoft Security Client
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E31AD2E7-7018-4085-88B0-3FFCCF8AE9C9}" = Microsoft DirectX 9.0 Developer Runtime for x64
"{E4F4D532-3BAF-3B8C-A395-0911AC0B0DFE}" = Microsoft Visual Studio 2010 Office Developer Tools (x64) Language Pack - JPN
"{E5748D30-7E6D-3A8E-BFE6-C1D02C6DDABB}" = Microsoft Help Viewer 1.1
"{EC13D94D-B308-3C76-81CB-89386AEE18D7}" = Visual Studio 2010 Prerequisites - English
"{F43ADE73-2880-4A95-B995-4FE386ECF667}" = Microsoft SQL Server 2008 Setup Support Files
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-X64 8.0.5.3_WHQL
"Lhaz" = Lhaz
"Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1
"Microsoft Help Viewer 1.1 Language Pack - JPN" = Microsoft Help Viewer 1.1 Language Pack - JPN
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"Microsoft Team Foundation Server 2010 Object Model - JPN" = Microsoft Team Foundation Server 2010 オブジェクト モデル - 日本語
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - JPN" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0044AEC7-8924-4FB1-B4F7-FD14A5FEA9E4}" = RPGツクール2003 ランタイムパッケージ
"{014A2868-BE56-4888-A16C-693989B8F153}" = SlimDX Runtime .NET 2.0 (January 2012)
"{019EF473-6D0A-415C-9A2E-1AF5F66AC60F}" = Windows Live Messenger
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}" = Sonic Focus
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{10AB1F40-BDEC-4A8D-B427-30F9429378B0}" = Windows Live Movie Maker
"{12176DDA-76A7-41AC-9C37-78D662C0FC2B}" = Dotfuscator Software Services - Community Edition - JPN
"{15D95497-8F76-41E5-8894-EDDB59E39BD9}" = Windows Live メール
"{15DF7630-7E1A-4DD1-A964-2B8F253FE05C}" = Microsoft SQL Server 2008 Browser
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1AA5BD63-6614-44B2-88A7-605191EDB835}" = Dotfuscator Software Services - Community Edition
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83218060F0}" = Java 8 Update 60
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{2F2E6B20-C46E-338E-AD50-310CDCB01507}" = Microsoft Visual Studio 2010 Professional - JPN
"{2F8B731A-5F2D-3EA8-8B25-C3E5E43F4BDB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33F7A957-A66D-45A1-BADF-6576083B14E2}" = RPGツクール2000 ランタイムパッケージ
"{38636216-B3E8-4A73-B5F4-D00A4A290650}" = Microsoft Silverlight 4 SDK - 日本語
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3EE9923D-3045-46AB-9CAA-E375993AEB4A}" = Intel(R) Driver Update Utility 2.2
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5172E572-C175-4F80-A6D5-5CB45826AD61}" = SceneSwitch
"{536DD37D-90EE-41DB-AEAA-ED9AA7488714}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 JPN
"{5AB776A5-8116-37FC-9788-C3E80E2AC1D4}" = Microsoft Visual F# 2.0 Runtime Language Pack - 日本語
"{5AB7D739-1735-3A9E-BE73-C43507CB4E6F}" = Microsoft Visual Studio 2010 Service Pack 1
"{5BA92669-B090-4767-9ED6-8D4F9B89DFAB}" = Microsoft SQL Server 2008 R2 データ層アプリケーション フレームワーク
"{5D757758-65D1-33E0-894F-A417D43B1B38}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{62BBB2F0-E220-4821-A564-730807D2C34D}" = Realtek USB 2.0 Reader Driver
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65E40D94-5C26-49CA-925F-8010E61D5F6C}" = Microsoft SQL Server 2008 R2 データ層アプリケーション プロジェクト
"{675D8E1E-2388-4718-902C-E5FC4888AC0E}" = Windows Live Essentials
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C3F8916-D6A5-4A31-9DA8-80C973CE437F}" = Windows Live Writer
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7134EF35-DA07-41F8-A71F-66709E194BB5}" = Windows Live Mesh
"{749F674B-2674-47E8-879C-5626A06B2A91}" = InstantOn for NB
"{7ADAC5B9-BAD3-37AF-A07D-D97847FF5D33}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{7C056FA6-E362-467B-8160-062E9474FEE5}" = SlimDX Redistributable for .NET 2.0 (September 2011)
"{8150221C-8F7E-4997-AD4E-AFDEE7F4B410}" = Wireless Console 3
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{85467CBC-7A39-33C9-8940-D72D9269B84F}" = Microsoft Visual F# 2.0 Runtime
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{88A686A9-D687-4295-B633-50D8A4B88371}" = Windows Live Writer Resources
"{89E9AB79-7914-4B67-8D4E-A8B1E39C3D89}" = Microsoft SQL Server Compact 3.5 SP2 JPN
"{8A66A2C8-0032-4949-8D99-C293A3EACF79}" = Windows Live Photo Common
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D59BE38-3A4F-4525-AD0D-8980E9E31EFA}" = Windows Live フォト ギャラリー
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0411-0000-0000000FF1CE}" = Microsoft Office Access MUI (Japanese) 2010
"{90140000-0016-0411-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Japanese) 2010
"{90140000-0018-0411-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Japanese) 2010
"{90140000-0019-0411-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Japanese) 2010
"{90140000-001A-0411-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Japanese) 2010
"{90140000-001B-0411-0000-0000000FF1CE}" = Microsoft Office Word MUI (Japanese) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0411-0000-0000000FF1CE}" = Microsoft Office Proof (Japanese) 2010
"{90140000-0028-0411-0000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2010
"{90140000-002C-0411-0000-0000000FF1CE}" = Microsoft Office Proofing (Japanese) 2010
"{90140000-0044-0411-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Japanese) 2010
"{90140000-006E-0411-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Japanese) 2010
"{90140000-00A1-0411-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Japanese) 2010
"{90140000-00BA-0411-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Japanese) 2010
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97C08405-B93D-44D9-B850-56B63C4936B8}" = Microsoft SQL Server 2008 R2 Transact-SQL 言語サービス
"{98f335cd-0a32-4b3f-b74c-ef9480e834f0}" = インテル® チップセット デバイス ソフトウェア
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A74A0091-5290-4EB8-B708-11AAA1BCEA6B}" = Microsoft SQL Server System CLR Types
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio
"{AC76BA86-0804-1033-1959-001824147215}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1041-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Japanese
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{AECA3622-E634-4A55-A696-70A511CBE06E}" = ASUS USB Charger Plus
"{B2DB883F-1AF3-4BE6-BE04-710D9C556C44}" = PowerWiz
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR
"{BAF0CA91-4642-46C8-9BCD-C93B61508701}" = リモート接続用の Windows Live Mesh ActiveX コントロール (日本語)
"{BF01E39C-5B68-4AD8-8DF1-9A37356D43F4}" = Microsoft SQL Server 2008 R2 管理オブジェクト
"{C0C7C6B3-4172-4296-ABFD-C176AE8FA1D2}" = Microsoft Silverlight 3 SDK - 日本語
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{ca4bc3a8-b99c-4416-90d8-351a8ceab458}" = Intel Driver Update Utility
"{CCB6898B-6470-417C-A0EE-DB7485E73A26}" = Microsoft Sync Framework SDK v1.0 SP1 ja
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D39F0676-163E-4595-A917-E28F99BBD4D2}" = ASUS AI Recovery
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}" = WCF RIA Services V1.0 SP1
"{DAD74137-2B54-4434-9630-B5DF176F5D3A}" = Microsoft ASP.NET MVC 2 - JPN
"{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}" = Microsoft ASP.NET MVC 2
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E764C46D-C726-403B-9874-4E35F2CACDBE}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - JPN
"{E80A8B4A-0CAF-3AD8-8A7E-74B4CC5A07DC}" = Microsoft Visual Studio Macro Tools - JPN Language Pack
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (October 2004)
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{EE03B0F1-7579-4CDD-BA63-BA37A8B9E2DB}" = Microsoft DirectX 9.0 SDK Update (October 2004)
"{EE408577-9C0E-4E5F-BCB2-DB5B3A220958}" = Windows Live UX Platform Language Pack
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F76E8352-DB67-4B74-8C77-C0C040F7D642}" = Prominence
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ASUS WebStorage" = ASUS WebStorage
"AsusScr_U_24_Series_ENG" = AsusScr_U_24_Series_ENG
"Google Chrome" = Google Chrome
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"MetasequoiaLE R3,0" = MetasequoiaLE R3.0
"Microsoft Visual Studio 2010 Professional - JPN" = Microsoft Visual Studio 2010 Professional - 日本語
"Microsoft Visual Studio 2010 Service Pack 1" = Microsoft Visual Studio 2010 Service Pack 1
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Microsoft Visual Studio Macro Tools - JPN Language Pack" = Microsoft Visual Studio Macro Tools - JPN Language Pack
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Revo Uninstaller" = Revo Uninstaller 1.95
"RGSS-RTP Standard_is1" = RGSS-RTP Standard
"RPGVX_J_is1" = RPGツクールVX
"RPGVXAce_RTP_is1" = RPGツクールVX Ace RTP
"RPGツクールVX RTP_is1" = RPGツクールVX RTP
"WinLiveSuite" = Windows Live Essentials

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-3922431837-200563891-1274897566-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2015/09/04 6:29:30 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0x2c0 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc9557b005 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: 580b503e-de1e-48ed-ba79-edef117e9962 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:30 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0xbb0 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc957d8555 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: 822b5e08-224e-439f-ad83-c2b1a34183c7 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:31 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0x3f8 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc959fc2a8 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: 54eaa168-b51d-4618-9066-990d266b6917 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:30 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

Error - 2015/09/04 6:29:30 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

Error - 2015/09/04 6:29:31 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

Error - 2015/09/04 6:29:32 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0x690 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc963243d8 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: 768fbd5d-d4e5-409f-8ee5-22c8db8c0d0e 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:32 | Computer Name = 【ユーザー名】-PC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: SearchUI.exe、バージョン: 10.0.10240.16431、タイム スタンプ:
0x55c9bba1 障害が発生しているモジュール名: CortanaApi.dll、バージョン: 0.0.0.0、タイム スタンプ: 0x55bebfac 例外コード:
0x80000003 障害オフセット: 0x0000000000151c23 障害が発生しているプロセス ID: 0x96c 障害が発生しているアプリケーションの開始時刻:
0x01d0e6fc969314f7 障害が発生しているアプリケーション パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
障害が発生しているモジュール
パス: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
レポート
ID: c2a43d65-bdb1-4b51-a48a-0c3b058145a1 障害が発生しているパッケージの完全な名前: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
障害が発生しているパッケージに関連するアプリケーション
ID: CortanaUI

Error - 2015/09/04 6:29:32 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

Error - 2015/09/04 6:29:32 | Computer Name = 【ユーザー名】-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = アプリ Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI のライセンス認証がエラーで失敗しました:
-2147023170。詳しくは、Microsoft-Windows-TWinUI/Operational ログをご覧ください。

[ System Events ]
Error - 2015/09/04 6:30:29 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:30:29 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:30:29 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:30:29 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:30:31 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:32:03 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:32:09 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:32:52 | Computer Name = 【ユーザー名】-PC | Source = DCOM | ID = 10005
Description =

Error - 2015/09/04 6:33:30 | Computer Name = 【ユーザー名】-PC | Source = Service Control Manager | ID = 7001
Description = Net.Tcp Listener Adapter サービスは、次のエラーが原因で開始できなかった Net.Tcp Port Sharing
Service サービスに依存しています: %%1058

Error - 2015/09/04 6:33:58 | Computer Name = 【ユーザー名】-PC | Source = BTHUSB | ID = 327697
Description = ローカルの Bluetooth アダプターは不明なエラーが発生したため、使用されません。ドライバーはアンロードされました。


< End of report >
  • ぐぬぬ
  • 2015/09/09 (Wed) 20:14:30
回答は午前2時頃になりそうです
すみません私が処置ログを解析する時間がありませんので、
処置ログの解析が完了するのが午前2時くらいではないかと思われます。
お手数ですが今しばらくお待ちください。
  • IVNO
  • MAIL
  • 2015/09/09 (Wed) 20:21:16
お待たせしました
とりあえずしばらく寝てないのと精神的疲労があって意識朦朧としてます。
処置抜けあったら申し訳ないです。

メモ帳を起動させ、以下をコピペしてください。
なお、:OTL、:Files、:Commands等はOTLでの処理方法を決める命令文です。
削除なされないようご注意ください。

------コピペこの下より------
:OTL
SRV - [2013/08/26 19:27:44 | 003,233,806 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Tor\tor.exe -- (tor)
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
CHR - Extension: No name found = %userprofile%\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\
[2015/09/08 20:58:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2015/09/08 20:57:59 | 000,192,216 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2015/09/08 20:57:02 | 000,109,272 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys
[2015/09/03 21:38:12 | 000,000,000 | ---D | C] -- C:\Users\【ユーザー名】\AppData\Roaming\Malwarebytes
[2015/09/03 21:37:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015/08/28 18:17:54 | 000,505,344 | ---- | M] () -- C:\WINDOWS\SysNative\EditionUpgradeManagerObj.dll
:Files
C:\Program Files (x86)\Tor
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi
:Commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペこの上まで------

コピペが完了しましたら、分かりやすいお名前をつけて保存してください。
その後、PCをセーフモードで起動させてください。
再度OTLを起動させ、Custom Scan/Fixesの項目内に上記で保存した内容をコピペしてください。
今回は駆除作業のため、その他のチェック項目はありません。
赤い文字の[Run Fix]をクリックして処置を開始してください。
OTLの処置に従って進めてゆき、通常モードで再起動を行う前後いずれかに処置ログが表示されますので、
そちらのログを貼り付けてご連絡ください。
  • IVNO
  • MAIL
  • 2015/09/10 (Thu) 02:15:46
Re: DNSUnlockerの広告等々・・・
お疲れ様です。
現在進行形で助けて貰っている私が言うのもなんですが、お体を大切にしてくださいね。

それと、命令文の【ユーザー名】はそのままコピペしてしまったようです。
同じ命令文の【ユーザー名】の部分を実際のユーザー名に書き換えて再試行した方が宜しいでしょうか?

以下ログです。

All processes killed
========== OTL ==========
Service tor stopped successfully!
Service tor deleted successfully!
C:\Program Files (x86)\Tor\tor.exe moved successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
File %userprofile%\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0 not found.
C:\ProgramData\Malwarebytes' Anti-Malware (portable) folder moved successfully.
C:\Windows\SysNative\drivers\MBAMSwissArmy.sys moved successfully.
C:\Windows\SysNative\drivers\mbamchameleon.sys moved successfully.
Folder C:\Users\【ユーザー名】\AppData\Roaming\Malwarebytes\ not found.
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine folder moved successfully.
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Configuration folder moved successfully.
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware folder moved successfully.
C:\ProgramData\Malwarebytes folder moved successfully.
File move failed. C:\Windows\SysNative\EditionUpgradeManagerObj.dll scheduled to be moved on reboot.
File rity] not found.
File sethosts] not found.
File ptyflash] not found.
File ptyjava] not found.
File ptytemp] not found.
File eaterestorepoint] not found.
File boot] not found.

OTL by OldTimer - Version 3.2.69.0 log created on 09102015_184604

Files\Folders moved on Reboot...
File move failed. C:\Windows\SysNative\EditionUpgradeManagerObj.dll scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ぐぬぬ
  • 2015/09/10 (Thu) 19:02:08
今一度OTLで処置を
さきほどのものは私が書き換えを忘れていました。
しかしOTLが正常に終了していないため、以下のスクリプトで処置をやり直しましょう。
ただ最近はOTLの動作が不安定ですので、今一度処置していただく場合もあります。

------コピペこの下より------
:Files
C:\Program Files (x86)\Tor
%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi
%appdata%\Malwarebytes
:Commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペこの上まで------
  • IVNO
  • MAIL
  • 2015/09/10 (Thu) 20:05:40
Re: DNSUnlockerの広告等々・・・
作業完了しました。

以下ログです。

All processes killed
========== FILES ==========
C:\Program Files (x86)\Tor folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_metadata folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\zu folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\zh_TW folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\zh_HK folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\zh_CN folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\vi folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ur folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\uk folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\tr folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\th folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\te folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ta folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\sw folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\sv folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\sr folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\sl folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\sk folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\si folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ru folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ro folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\pt_PT folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\pt_BR folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\pl folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\no folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\nl folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ne folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ms folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\mr folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\mn folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ml folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\lv folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\lt folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\lo folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ko folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\kn folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\km folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ka folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ja folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\iw folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\it folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\is folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\id folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\hy folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\hu folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\hr folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\hi folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\gu folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\gl folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\fr_CA folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\fr folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\fil folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\fi folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\fa folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\eu folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\et folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\es_419 folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\es folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\en_US folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\en_GB folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\el folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\de folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\da folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\cs folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ca folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\bn folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\bg folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\az folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\ar folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\am folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales\af folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\_locales folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0 folder moved successfully.
C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi folder moved successfully.
C:\Users\【ユーザー名】\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine folder moved successfully.
C:\Users\【ユーザー名】\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs folder moved successfully.
C:\Users\【ユーザー名】\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware folder moved successfully.
C:\Users\【ユーザー名】\AppData\Roaming\Malwarebytes folder moved successfully.
File\Folder :Commands not found.
File\Folder [purity] not found.
File\Folder [resethosts] not found.
File\Folder [emptyflash] not found.
File\Folder [emptyjava] not found.
File\Folder [emptytemp] not found.
File\Folder [createrestorepoint] not found.
File\Folder [reboot] not found.

OTL by OldTimer - Version 3.2.69.0 log created on 09102015_202053

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ぐぬぬ
  • 2015/09/10 (Thu) 20:28:44
案の定ですが今一度OTLで処置を
予想通り、OTLはまた正常に動作しませんでした。
次はこれしか設定しないので確実にいけるはずです。

------コピペこの下より------
:Commands
[purity]
[resethosts]
[emptyflash]
[emptyjava]
[emptytemp]
[createrestorepoint]
[reboot]
------コピペこの上まで------
  • IVNO
  • MAIL
  • 2015/09/10 (Thu) 20:33:15
Re: DNSUnlockerの広告等々・・・
返信が遅れてしまい申し訳ありません。

以下ログです。

All processes killed
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: Administrator

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Default.migrated

User: Guest

User: Public

User: 【ユーザー名】
->Flash cache emptied: 36552 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: Administrator

User: All Users

User: Default

User: Default User

User: Default.migrated

User: Guest

User: Public

User: 【ユーザー名】
->Java cache emptied: 0 bytes

Total Java Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default.migrated

User: Guest

User: Public

User: 【ユーザー名】
->Temp folder emptied: 49155034 bytes
->Temporary Internet Files folder emptied: 976259681 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 157817 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 978.00 mb

Unable to start System Restore Service. Error code 1084

OTL by OldTimer - Version 3.2.69.0 log created on 09102015_215355

Files\Folders moved on Reboot...
C:\Users\【ユーザー名】\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • ぐぬぬ
  • 2015/09/10 (Thu) 22:03:41
状況報告をお願いいたします
OTLでの処置は正常に完了した模様です。
PCは現在はどのような状態でしょうか。
  • IVNO
  • MAIL
  • 2015/09/11 (Fri) 03:33:54
Re: DNSUnlockerの広告等々・・・
先ほど確認しましたが、MicrosoftEDGEでずっとあった青文字がなくなりました!
正直なところ目につく度に嫌な気分を味わっていたので、すごくありがたいです!
今のところその他に変な挙動はありません。
本当にありがとうございます!
  • ぐぬぬ
  • 2015/09/11 (Fri) 21:22:45
しばらく様子を見てみましょう
現状では以上なしと言うことですね。
しかし私自身、結局どれがトリガーとなって沈静化したのか分かりません。
よって再発の可能性もあると言うことです。
一度ここで様子見期間を設け、その後続けて処置をしましょう。
表面上では出ていなくても水面下で稼動している場合もあります。
それらも見つけて根こそぎしょちするためにも、
それらが顔を見せる1週間程度は様子見を行ってください。
その後、HJTのログ、CCのインストール情報ログを添え、
状況報告を添えてご連絡をお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/11 (Fri) 22:33:18
Re: DNSUnlockerの広告等々・・・
わかりました。
また1週間後に報告します。
  • ぐぬぬ
  • 2015/09/11 (Fri) 23:09:28
Re: DNSUnlockerの広告等々・・・
お久しぶりです。

あれから毎日時間があればインターネットを使用していますが、
今のところ報告いたしましたような現象は発生しておりません。
  • ぐぬぬ
  • 2015/09/18 (Fri) 23:11:26
ログのご提示を
現段階では問題が再発した様子はないと言うことですね。
それではログ上での再発が観測されないかの確認のため、
前回のご案内に従ってログのご提示をお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/19 (Sat) 00:35:10
Re: DNSUnlockerの広告等々・・・
返信が遅れてしまい申し訳ありません。

以下ログです。

CC

Adobe Acrobat Reader DC - Japanese Adobe Systems Incorporated 2015/09/02 206 MB 15.008.20082
Adobe AIR Adobe Systems Incorporated 2015/08/28 4.0.0.1390
Adobe Flash Player 10 Plugin Adobe Systems Incorporated 2015/08/28 10.0.32.18
Asmedia ASM104x USB 3.0 Host Controller Driver Asmedia Technology 2012/04/17 2.27 MB 1.12.5.0
ASUS AI Recovery ASUS 2012/10/13 11.5 MB 1.0.27
ASUS LifeFrame3 ASUS 2012/04/17 30.2 MB 3.0.22
ASUS Live Update ASUS 2012/04/17 3.97 MB 3.0.6
ASUS Power4Gear Hybrid ASUS 2012/04/17 13.2 MB 1.1.45
ASUS Secure Delete ASUS 2012/04/17 6.35 MB 1.00.0007
ASUS SmartLogon ASUS 2012/04/17 11.1 MB 1.0.0011
ASUS Splendid Video Enhancement Technology ASUS 2012/04/17 19.2 MB 1.02.0033
ASUS USB Charger Plus AsusTek Computer Inc. 2012/04/17 2.0.2
ASUS Virtual Camera asus 2012/04/17 3.13 MB 1.0.21
ASUS WebStorage eCareme Technologies, Inc. 2015/08/28 3.0.108.222
AsusScr_U_24_Series_ENG ASUS 2015/08/28 159 MB 1.0.0001
Atheros Client Installation Program Atheros 2012/04/17 7.0
ATK Package ASUS 2012/04/17 12.0 MB 1.0.0013
Bluetooth Win7 Suite (64) Atheros Communications 2012/04/17 59.4 MB 7.02.000.55
CCleaner Piriform 2015/09/01 5.09
CyberLink LabelPrint CyberLink Corp. 2012/04/17 49.8 MB 2.5.3624
CyberLink Media Suite CyberLink Corp. 2012/04/17 40.4 MB 8.0.2926
CyberLink Power2Go CyberLink Corp. 2012/04/17 223 MB 7.0.0.1126
Dotfuscator Software Services - Community Edition PreEmptive Solutions 2013/03/29 6.45 MB 5.0.2500.0
Dotfuscator Software Services - Community Edition - JPN PreEmptive Solutions 2012/05/30 3.07 MB 5.0.2300.0
ETDWare PS/2-X64 8.0.5.3_WHQL ELAN Microelectronic Corp. 2015/08/28 8.0.5.3
Fast Boot ASUS 2012/04/17 1.46 MB 1.0.10
Google Chrome Google Inc. 2012/03/02 45.0.2454.93
Google Toolbar for Internet Explorer Google Inc. 2015/08/28 7.5.6710.2136
InstantOn for NB ASUS 2012/04/17 4.27 MB 2.1.3
Intel Driver Update Utility Intel 2015/08/28 19.6 MB 2.2.0.2
Intel(R) Control Center Intel Corporation 1.2.1.1007
Intel(R) Management Engine Components Intel Corporation 7.0.0.1144
Intel(R) Processor Graphics Intel Corporation 9.17.10.2932
Java 8 Update 60 Oracle Corporation 2015/08/28 20.6 MB 8.0.600.27
Lhaz ちとらソフト 2015/08/28 2.2.4
MetasequoiaLE R3.0 2015/08/28
Microsoft .NET Framework 4 Multi-Targeting Pack Microsoft Corporation 2012/05/30 83.4 MB 4.0.30319
Microsoft ASP.NET MVC 2 Microsoft Corporation 2014/10/16 482 KB 2.0.60926.0
Microsoft ASP.NET MVC 2 - JPN Microsoft Corporation 2012/05/30 25.0 KB 2.0.50331.0
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools Microsoft Corporation 2012/05/30 2.25 MB 2.0.50217.0
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - JPN Microsoft Corporation 2012/05/30 2.13 MB 2.0.50402.0
Microsoft DirectX 9.0 SDK Update (October 2004) Microsoft® Corporation 2012/05/30 337 MB 9.02.3900
Microsoft Help Viewer 1.1 Microsoft Corporation 2015/08/28 3.97 MB 1.1.40219
Microsoft Help Viewer 1.1 Language Pack - JPN Microsoft Corporation 2015/08/28 1.95 MB 1.1.40219
Microsoft Office Professional Plus 2010 Microsoft Corporation 2015/08/28 14.0.7015.1000
Microsoft Silverlight Microsoft Corporation 2015/08/13 348 MB 5.1.40728.0
Microsoft Silverlight 3 SDK - 日本語 Microsoft Corporation 2012/05/30 33.3 MB 3.0.40818.0
Microsoft Silverlight 4 SDK - 日本語 Microsoft Corporation 2013/03/29 53.1 MB 4.0.50826.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 2012/03/02 1.69 MB 3.1.0000
Microsoft SQL Server 2008 (64-bit) Microsoft Corporation 2015/08/28
Microsoft SQL Server 2008 Browser Microsoft Corporation 2013/03/29 7.97 MB 10.3.5500.0
Microsoft SQL Server 2008 Native Client Microsoft Corporation 2013/03/29 7.07 MB 10.3.5500.0
Microsoft SQL Server 2008 R2 Transact-SQL 言語サービス Microsoft Corporation 2013/03/29 6.79 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 データ層アプリケーション フレームワーク Microsoft Corporation 2013/03/29 5.61 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 データ層アプリケーション プロジェクト Microsoft Corporation 2013/03/29 14.1 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 管理オブジェクト Microsoft Corporation 2013/03/29 14.4 MB 10.50.1750.9
Microsoft SQL Server 2008 R2 管理オブジェクト (x64) Microsoft Corporation 2013/03/29 6.59 MB 10.50.1750.9
Microsoft SQL Server 2008 Setup Support Files Microsoft Corporation 2015/07/16 54.2 MB 10.3.5538.0
Microsoft SQL Server Compact 3.5 SP2 JPN Microsoft Corporation 2012/05/30 3.66 MB 3.5.8080.0
Microsoft SQL Server Compact 3.5 SP2 x64 JPN Microsoft Corporation 2012/05/30 4.78 MB 3.5.8080.0
Microsoft SQL Server Database Publishing Wizard 1.4 Microsoft Corporation 2012/05/30 10.1 MB 10.1.2512.8
Microsoft SQL Server System CLR Types Microsoft Corporation 2013/03/29 991 KB 10.50.1750.9
Microsoft SQL Server System CLR Types (x64) Microsoft Corporation 2013/03/29 870 KB 10.50.1750.9
Microsoft SQL Server VSS Writer Microsoft Corporation 2013/03/29 4.02 MB 10.3.5500.0
Microsoft Sync Framework Runtime v1.0 SP1 (x64) ja Microsoft Corporation 2012/05/30 1.06 MB 1.0.3010.0
Microsoft Sync Framework SDK v1.0 SP1 ja Microsoft Corporation 2012/05/30 30.1 MB 1.0.3010.0
Microsoft Sync Framework Services v1.0 SP1 (x64) ja Microsoft Corporation 2012/05/30 2.92 MB 1.0.3010.0
Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) ja Microsoft Corporation 2012/05/30 630 KB 2.0.3010.0
Microsoft Team Foundation Server 2010 オブジェクト モデル - 日本語 Microsoft Corporation 2015/08/28 10.0.40219
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 2012/06/04 300 KB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 2014/05/28 230 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 2012/04/17 596 KB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 Microsoft Corporation 2012/05/30 599 KB 9.0.30729.4974
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 2012/06/04 600 KB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319 Microsoft Corporation 2012/05/30 314 KB 10.0.30319
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/16 13.8 MB 10.0.40219
Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 Microsoft Corporation 2013/03/29 20.5 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 2014/10/16 11.1 MB 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 Microsoft Corporation 2013/03/29 15.9 MB 10.0.40219
Microsoft Visual F# 2.0 Runtime Microsoft Corporation 2013/03/29 5.84 MB 10.0.40219
Microsoft Visual F# 2.0 Runtime Language Pack - 日本語 Microsoft Corporation 2012/05/30 1.34 MB 10.0.30319
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools Microsoft Corporation 2013/03/29 35.4 MB 10.0.40219
Microsoft Visual Studio 2010 Professional - 日本語 Microsoft Corporation 2015/08/28 10.0.30319
Microsoft Visual Studio 2010 Service Pack 1 Microsoft Corporation 2015/08/28 75.9 MB 10.0.40219
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Corporation 2015/08/28 10.0.50903
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語 Microsoft Corporation 2015/08/28 10.0.50903
Microsoft Visual Studio Macro Tools Microsoft Corporation 2015/08/28 9.0.30729
Microsoft Visual Studio Macro Tools - JPN Language Pack Microsoft Corporation 2015/08/28 9.0.30729
PowerWiz ASUS 2012/04/17 6.89 MB 1.0.3
Prominence 2015/08/28
Realtek Ethernet Controller Driver Realtek 2012/04/17 7.44.421.2011
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 2015/08/28 6.0.1.7535
Realtek USB 2.0 Reader Driver Realtek Semiconductor Corp. 2012/04/17 6.1.7600.10008
Revo Uninstaller 1.95 VS Revo Group 2015/08/28 1.95
RGSS-RTP Standard Enterbrain 2013/04/27 1.03
RPGツクール2000 ランタイムパッケージ 2015/08/28
RPGツクールVX Enterbrain 2013/11/12 140 MB 1.03a
RPGツクールVX Ace RTP Enterbrain 2013/11/10 194 MB 1.00
RPGツクールVX RTP Enterbrain 2013/11/12 42.1 MB 1.02
RPGツクール2003 ランタイムパッケージ 2015/08/28
SceneSwitch ASUS 2012/04/17 2.22 MB 1.0.8
SlimDX Redistributable for .NET 2.0 (September 2011) SlimDX Group 2014/04/12 15.5 MB 2.0.12.43
SlimDX Runtime .NET 2.0 (January 2012) SlimDX Group 2014/04/12 17.2 MB 2.0.13.43
Sonic Focus Synopsys 2012/04/17 4.31 MB 1.0.0.4
Synaptics Pointing Device Driver Synaptics Incorporated 2015/08/28 46.4 MB 19.0.9.5
Unity Web Player Unity Technologies ApS 2015/08/28 12.0 MB
Visual Studio 2010 Prerequisites - English Microsoft Corporation 2013/03/29 23.2 MB 10.0.40219
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 JPN Microsoft Corporation 2012/05/30 11.2 MB 4.0.8080.0
WCF RIA Services V1.0 SP1 Microsoft Corporation 2013/03/29 12.3 MB 4.1.60114.0
Web Deployment Tool Microsoft Corporation 2012/05/30 3.10 MB 1.1.0618
Windows Live Essentials Microsoft Corporation 2012/03/02 15.4.3538.0513
WinFlash ASUS 2012/04/17 856 KB 2.31.1
Wireless Console 3 ASUS 2012/04/17 9.05 MB 3.0.21
インテル(R) ターボ・ブースト・テクノロジー・モニター 2.0 インテル 2012/04/17 13.2 MB 2.1.23.0
リモート接続用の Windows Live Mesh ActiveX コントロール (日本語) Microsoft Corporation 2012/03/02 5.57 MB 15.4.5722.2
---------------------------------------------------------------------------------
HJT

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 2:59:39, on 2015/09/19
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)


Boot mode: Safe mode

Running processes:
C:\Users\【ユーザー名】\Downloads\HijackThis.exe

O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: OneNote に送る(&N) - res://C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Update サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10416 bytes
  • ぐぬぬ
  • 2015/09/19 (Sat) 03:08:30
GUで削除し追加のログ取得を
ログを確認いたしましたが、いまだに更新できていないソフトウェアがあります。
GUを利用して以下を削除なされてください。

Adobe Flash Player 10 Plugin Adobe Systems Incorporated 2015/08/28 10.0.32.18

削除が完了しましたら、CCのスタートアップのすべてのタブのログを取得し、
それらを貼り付けてご連絡をお願いいたします。
  • IVNO
  • MAIL
  • 2015/09/19 (Sat) 09:30:04
Re: DNSUnlockerの広告等々・・・
作業完了いたしました。
削除とは強制削除でよろしかったでしょうか?
一応関連ファイルとして出て来たものすべて削除しました。

以下ログです。

windows

有効 HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
有効 HKCU:Run OneDrive Microsoft Corporation "C:\Users\【ユーザー名】\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
有効 HKCU:Run swg Google Inc. "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
無効 HKLM:Run Adobe Reader Speed Launcher "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
無効 HKLM:Run ASUS Screen Saver Protector ASUS C:\Windows\AsScrPro.exe
有効 HKLM:Run ASUSPRP ASUSTek Computer Inc. "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
有効 HKLM:Run ASUSWebStorage ecareme C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
有効 HKLM:Run AthBtTray Atheros Commnucations "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
有効 HKLM:Run AtherosBtStack "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
有効 HKLM:Run ATKMEDIA ASUS C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
有効 HKLM:Run ATKOSD2 ASUS C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
有効 HKLM:Run BCSSync Microsoft Corporation "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
無効 HKLM:Run CLMLServer CyberLink "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
有効 HKLM:Run ETDCtrl %ProgramFiles%\Elantech\ETDCtrl.exe
有効 HKLM:Run HControlUser ASUS C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
有効 HKLM:Run HotKeysCmds Intel Corporation "C:\WINDOWS\system32\hkcmd.exe"
有効 HKLM:Run IgfxTray Intel Corporation "C:\WINDOWS\system32\igfxtray.exe"
有効 HKLM:Run IME14 JPN Setup Microsoft Corporation C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
有効 HKLM:Run IntelTBRunOnce Microsoft Corporation wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
有効 HKLM:Run Persistence Intel Corporation "C:\WINDOWS\system32\igfxpers.exe"
有効 HKLM:Run RtHDVBg Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
無効 HKLM:Run RtHDVCpl Realtek Semiconductor C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
有効 HKLM:Run SonicMasterTray Virage Logic Corporation / Sonic Focus C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
有効 HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
有効 HKLM:Run SynTPEnh Synaptics Incorporated %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
有効 HKLM:Run Wireless Console 3 ASUS C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
-------------------------------------------------------------------------------
IE

有効 Extension OneNote に送る Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote に送る Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension OneNote リンク ノート(K) Microsoft Corporation C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
有効 Extension Send by Bluetooth to Atheros Commnucations C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
有効 Extension このコンテンツを引用 Microsoft Corporation C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
無効 Helper CIESpeechBHO Class Atheros Commnucations C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
有効 Helper Google Toolbar Helper Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
有効 Helper Google Toolbar Helper Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
無効 Helper Groove GFS Browser Helper Microsoft Corporation C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
無効 Helper Groove GFS Browser Helper Microsoft Corporation C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
無効 Helper Java(tm) Plug-In 2 SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
無効 Helper Java(tm) Plug-In SSV Helper Oracle Corporation C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
有効 Helper Office Document Cache Handler Microsoft Corporation C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
有効 Toolbar Google Toolbar Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
有効 Toolbar Google Toolbar Google Inc. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
---------------------------------------------------------------------------------
GoogleChrome

有効 App Gmail 8.1 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0
有効 App Google Search 0.0.0.30 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0
有効 App Google ドライブ 14.0 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.0_0
有効 App YouTube 4.2.7 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0
有効 Extension Google スプレッドシート 1.1 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0
有効 Extension Google スライド 0.9 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0
有効 Extension Google ドキュメント 0.9 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0
有効 Extension Google ドキュメント オフライン 0.5 最初のユーザー C:\Users\【ユーザー名】\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0
---------------------------------------------------------------------------------
スケジュールされたタスク

有効 Task ACMON ASUS C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
有効 Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
有効 Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
有効 Task ASUS Live Update ASUSTeK Computer Inc. C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
有効 Task ASUS P4G ASUS C:\Program Files\P4G\BatteryLife.exe
有効 Task ASUS Secure Delete C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
有効 Task ASUS SmartLogon Console Sensor ASUS C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
有効 Task ATKOSD2 ASUS C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
有効 Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
有効 Task DNSATLANTIC C:\Program Files (x86)\DNS Unlocker\dnsatlantic.exe /Scheduled
有効 Task GoogleUpdateTaskMachineCore Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
有効 Task GoogleUpdateTaskMachineUA Google Inc. C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
有効 Task SidebarExecute C:\Program Files\Windows Sidebar\sidebar.exe /addGadget
有効 Task USBChargerPlus ASUSTek Computer Inc. C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
  • ぐぬぬ
  • 2015/09/19 (Sat) 12:37:46
最後の処置を行い自衛しつつ解決で
最後の処置を行いましょう。
今回の処置は、今後の再感染を防止するための自衛措置のひとつとなります。
セキュリティソフトを起動させ、設定を開いてください。
PUP(不審なソフトウェア)の検出機能があれば、そちらを有効な状態に設定してください。
PUPの検出機能につきましては、ご利用のセキュリティソフトにより名称や設定方法が異なるため、
有料版のセキュリティソフトをご利用の場合は、セキュリティベンダーにお問い合わせいただくのが手っ取り早いでしょう。
セキュリティソフトでは、スキャンに非常に時間がかかるようになると言う理由により、
初期状態では圧縮フォルダ内はスキャンしない設定になっていることが大半です。
しかしこの機能が標準では無効になっていることを利用して、PC内に潜入するマルウェアも多いです。
セキュリティを向上させるため、スキャン設定の項目で圧縮フォルダ内もスキャンを行う設定を有効にしてください。
ヒューリスティック検知あるいはスキャンを有効にする項目があれば、そちらも有効になされてください。
レピュテーション(評価)機能を有効にする項目があれば、こちらも有効になされてください。
スキャン対象が限定されている場合、全体をスキャンするように設定変更を行ってください。
以上で最後の処置を行いますが、この最後の処置は回答者により異なるため、
ほかの回答者の方の処置案内も確認され、今後の自衛策に役立てると良いでしょう。

問題もないようですので、以下に記載する自衛を遵守しつつ、本件を解決といたしましょう。
再度感染しないように、Windows Updateを怠らない、怪しいサイトには行かない、フリーウェアは極力使わない、
P2Pファイル共有ソフトには一切手を出さないなどの「自衛」はしっかりと行ってください。
こちらの富士通のURLにもいくつか詳しく記述されていますのでご覧ください。
https://azby.fmworld.net/usage/closeup/20110629/?usagefrom=closeup
また上記でも記述いたしましたが、ほかの方の質問や回答を見て、色々なものへの対応策を身につけるのも一つの自衛です。
近年情報流出が激化しておりますが、セキュリティソフトだけではこのようなマルウェアは防げません。
セキュリティソフトは、「常に後手」であるソフトウェアです。
これは、誰かが新種ウイルスに感染し、その感染が報告されない限り、
セキュリティソフトのベンダーとしてもウイルスに対応することができないのです。
ですので、セキュリティソフトは自衛のためのサポートツールであるということを常に念頭に置き、
今回のような他人に頼らざるを得ない状況となった伏魔殿での苦い経験を今後の糧に、
ご自身のPCと真剣に向き合いつつ、有益で安全なPCライフを実現してゆきましょう。
なお自衛は今だけの話ではなく、PCを扱う限り一生行うようにしましょう。
今回使用したツールはすべて導入時の案内に沿って片付けておいてください。
それではご安全に。
  • IVNO
  • MAIL
  • 2015/09/19 (Sat) 16:31:41
Re: DNSUnlockerの広告等々・・・
ありがとうございました!
これからはより一層気を付けようと思います。
  • ぐぬぬ
  • 2015/09/19 (Sat) 17:15:37

返信フォーム※初心者、通りすがり等、重複しやすい名前の利用はご遠慮ください。




プレビュー (投稿前に内容を確認)