Advertisement
Guest User

Untitled

a guest
Oct 3rd, 2013
104
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.95 KB | None | 0 0
  1. RogueKiller V8.7.1 [Oct 3 2013] by Tigzy
  2. mail : tigzyRK<at>gmail<dot>com
  3. Feedback : http://www.adlice.com/forum/
  4. Website : http://www.adlice.com/softwares/roguekiller/
  5. Blog : http://tigzyrk.blogspot.com/
  6.  
  7. Operating System : Windows 7 (6.1.7600 ) 32 bits version
  8. Started in : Normal mode
  9. User : Antony [Admin rights]
  10. Mode : Scan -- Date : 10/03/2013 18:32:10
  11. | ARK || FAK || MBR |
  12.  
  13. ¤¤¤ Bad processes : 0 ¤¤¤
  14.  
  15. ¤¤¤ Registry Entries : 8 ¤¤¤
  16. [HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
  17. [HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> FOUND
  18. [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
  19. [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> FOUND
  20. [HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
  21. [HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
  22. [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
  23. [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
  24.  
  25. ¤¤¤ Scheduled tasks : 0 ¤¤¤
  26.  
  27. ¤¤¤ Startup Entries : 0 ¤¤¤
  28.  
  29. ¤¤¤ Web browsers : 0 ¤¤¤
  30.  
  31. ¤¤¤ Particular Files / Folders: ¤¤¤
  32.  
  33. ¤¤¤ Driver : [LOADED] ¤¤¤
  34. [Address] SSDT[84] : NtCreateSection @ 0x82E841B3 -> HOOKED (Unknown @ 0x91AC8A5E)
  35. [Address] SSDT[299] : NtRequestWaitReplyPort @ 0x82EC9FAA -> HOOKED (Unknown @ 0x91AC8A68)
  36. [Address] SSDT[316] : NtSetContextThread @ 0x82F2F1AB -> HOOKED (Unknown @ 0x91AC8A63)
  37. [Address] SSDT[347] : NtSetSecurityObject @ 0x82E69397 -> HOOKED (Unknown @ 0x91AC8A6D)
  38. [Address] SSDT[368] : NtSystemDebugControl @ 0x82E5C66F -> HOOKED (Unknown @ 0x91AC8A72)
  39. [Address] SSDT[370] : NtTerminateProcess @ 0x82EB501D -> HOOKED (Unknown @ 0x91AC89FF)
  40. [Address] Shadow SSDT[585] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x91AC8A86)
  41. [Address] Shadow SSDT[588] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0x91AC8A8B)
  42. [Address] IAT @explorer.exe (GetProcAddress) : KERNEL32.dll -> HOOKED (C:\Windows\system32\apphelp.dll @ 0x752C5E25)
  43. [Inline] EAT @explorer.exe (RegisterClipboardFormatW) : pkmws.dll -> HOOKED (C:\Windows\system32\USER32.dll @ 0x7590EDFD)
  44.  
  45. ¤¤¤ External Hives: ¤¤¤
  46.  
  47. ¤¤¤ Infection : ¤¤¤
  48.  
  49. ¤¤¤ HOSTS File: ¤¤¤
  50. --> %SystemRoot%\System32\drivers\etc\hosts
  51.  
  52.  
  53.  
  54.  
  55. ¤¤¤ MBR Check: ¤¤¤
  56.  
  57. +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standard disk drives) - ST31000528AS ATA Device +++++
  58. --- User ---
  59. [MBR] 250b57680c3234531694b3382ecdc5e2
  60. [BSP] 177e45c7901afd183114ec3f50f18cd0 : Windows 7/8 MBR Code
  61. Partition table:
  62. 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
  63. 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 599900 Mo
  64. 2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1228802048 | Size: 353866 Mo
  65. User = LL1 ... OK!
  66. User = LL2 ... OK!
  67.  
  68. Finished : << RKreport[0]_S_10032013_183210.txt >>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement