Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- RogueKiller V10.7.0.0 [May 25 2015] by Adlice Software
- mail : http://www.adlice.com/contact/
- Feedback : http://forum.adlice.com
- Website : http://www.adlice.com/softwares/roguekiller/
- Blog : http://www.adlice.com
- Operating System : Windows 8 (6.2.9200 ) 64 bits version
- Started in : Normal mode
- User : maribell1 [Administrator]
- Started from : C:\Users\maribell1\Desktop\RogueKiller.exe
- Mode : Delete -- Date : 05/25/2015 16:26:54
- ¤¤¤ Processes : 1 ¤¤¤
- [Suspicious.Path] Windows Startupservice.exe(1572) -- C:\Users\maribell1\AppData\Roaming\Windows Startup\Windows Startupservice.exe[-] -> Killed [TermProc]
- ¤¤¤ Registry : 15 ¤¤¤
- [PUM.Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -> Not selected
- [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -> Not selected
- [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> Not selected
- [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> Not selected
- [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} -> Not selected
- [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-2178466231-3421997683-3247184078-1001\Software\Microsoft\Windows\CurrentVersion\Run | Windows Startup : "C:\Users\maribell1\AppData\Roaming\Windows Startup\Windows Startupservice.exe" [-] -> Deleted
- [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-2178466231-3421997683-3247184078-1001\Software\Microsoft\Windows\CurrentVersion\Run | Windows Startup : "C:\Users\maribell1\AppData\Roaming\Windows Startup\Windows Startupservice.exe" [-] -> ERROR [2]
- [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iscFlash (\??\C:\Users\ADMINI~1\AppData\Local\Temp\7zS5813.tmp\iscflashx64.sys) -> Deleted
- [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iscFlash (\??\C:\Users\ADMINI~1\AppData\Local\Temp\7zS5813.tmp\iscflashx64.sys) -> Deleted
- [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2178466231-3421997683-3247184078-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://acer13.msn.com -> Not selected
- [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2178466231-3421997683-3247184078-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://acer13.msn.com -> Not selected
- [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Not selected
- [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Not selected
- [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Not selected
- [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Not selected
- ¤¤¤ Tasks : 0 ¤¤¤
- ¤¤¤ Files : 2 ¤¤¤
- [Suspicious.Path][File] Adobe Dreamweaver.lnk -- C:\Users\maribell1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Dreamweaver.lnk [LNK@] C:\ProgramData\{de468cd3-df45-7c80-de46-68cd3df4334f}\Adobe Dreamweaver.exe --startup=1 -> Deleted
- [Suspicious.Path][File] CE80.lnk -- C:\Users\maribell1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CE80.lnk [LNK@] C:\ProgramData\{5a0d553e-b07f-7de1-5a0d-d553eb0754fa}\CE80.exe --startup=1 -> Deleted
- ¤¤¤ Hosts File : 0 ¤¤¤
- ¤¤¤ Antirootkit : 5 (Driver: Not loaded [0xc000036b]) ¤¤¤
- [IAT:Inl(Hook.IEAT)] (firefox.exe) USER32.dll - PeekMessageW : C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL @ 0x74b74230 (ret)
- [IAT:Inl(Hook.IEAT)] (firefox.exe) USER32.dll - GetMessageW : C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL @ 0x74b740e0 (ret)
- [IAT:Inl(Hook.IEAT)] (firefox.exe) USER32.dll - GetMessageA : C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL @ 0x74b74040 (ret)
- [IAT:Inl(Hook.IEAT)] (firefox.exe) USER32.dll - PeekMessageA : C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL @ 0x74b74180 (ret)
- [IAT:Inl(Hook.IEAT)] (firefox.exe) USER32.dll - IsDialogMessageW : C:\PROGRA~2\KEYCRY~1\KEYCRY~3.DLL @ 0x74b73fc0 (ret)
- ¤¤¤ Web browsers : 1 ¤¤¤
- [FIREFX:Addon] 8qz62uar.default : MEGA extension [firefox@mega.co.nz] -> Deleted
- ¤¤¤ MBR Check : ¤¤¤
- +++++ PhysicalDrive0: ST500LT012-9WS142 +++++
- --- User ---
- [MBR] f52a92d80b5c0bc50ee753c3c6829d56
- [BSP] b3ed8a006b54b0fba9e5b9afe6cbc64c : Empty MBR Code
- Partition table:
- 0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 400 MB
- 1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 821248 | Size: 300 MB
- 2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1435648 | Size: 128 MB
- 3 - Basic data partition | Offset (sectors): 1697792 | Size: 459972 MB
- 4 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 943720448 | Size: 16139 MB
- User = LL1 ... OK
- User = LL2 ... OK
- ============================================
- RKreport_SCN_05252015_155511.log
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement