Guest User

efralope_rogue_report_3_14_14

a guest
Mar 14th, 2014
214
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.86 KB | None | 0 0
  1. RogueKiller V8.8.10 [Feb 28 2014] by Adlice Software
  2. mail : http://www.adlice.com/contact/
  3. Feedback : http://forum.adlice.com
  4. Website : http://www.adlice.com/softwares/roguekiller/
  5. Blog : http://www.adlice.com
  6.  
  7. Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
  8. Started in : Normal mode
  9. User : Efrain [Admin rights]
  10. Mode : Remove -- Date : 03/14/2014 05:36:43
  11. | ARK || FAK || MBR |
  12.  
  13. ¤¤¤ Bad processes : 0 ¤¤¤
  14.  
  15. ¤¤¤ Registry Entries : 7 ¤¤¤
  16. [RUN][SUSP PATH] HKCU\[...]\Run : ROC_ROC_APR2013_AV (C:\Users\Efrain\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT --mid 1122584a03b8355d35d535141049523c-b4c6fe9c9646c256f265a909c6ce23396b9b1c9e --CMPID ROC_APR2013_AV --CMPIDEXTRA 2012 [x][x][x][x]) -> DELETED
  17. [RUN][SUSP PATH] HKCU\[...]\Run : AVG-Secure-Search-Update_0913a (C:\Users\Efrain\AppData\Roaming\AVG 0913a Campaign\AVG-Secure-Search-Update-0913a.exe /PROMPT --mid 1122584a03b8355d35d535141049523c-b4c6fe9c9646c256f265a909c6ce23396b9b1c9e --CMPID 0913a [x][x][x]) -> DELETED
  18. [RUN][SUSP PATH] HKUS\S-1-5-21-908756412-3643878856-3920343152-1000\[...]\Run : ROC_ROC_APR2013_AV (C:\Users\Efrain\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT --mid 1122584a03b8355d35d535141049523c-b4c6fe9c9646c256f265a909c6ce23396b9b1c9e --CMPID ROC_APR2013_AV --CMPIDEXTRA 2012 [x][x][x][x]) -> [0x2] The system cannot find the file specified.
  19. [RUN][SUSP PATH] HKUS\S-1-5-21-908756412-3643878856-3920343152-1000\[...]\Run : AVG-Secure-Search-Update_0913a (C:\Users\Efrain\AppData\Roaming\AVG 0913a Campaign\AVG-Secure-Search-Update-0913a.exe /PROMPT --mid 1122584a03b8355d35d535141049523c-b4c6fe9c9646c256f265a909c6ce23396b9b1c9e --CMPID 0913a [x][x][x]) -> [0x2] The system cannot find the file specified.
  20. [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowRun (0) -> REPLACED (1)
  21. [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
  22. [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
  23.  
  24. ¤¤¤ Scheduled tasks : 2 ¤¤¤
  25. [V2][SUSP PATH] Carbonite Upgrade Check : "C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe" - /silent [x] -> DELETED
  26. [V2][SUSP PATH] {5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} : "C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe" - /silent $(Arg0) [x][x] -> DELETED
  27.  
  28. ¤¤¤ Startup Entries : 1 ¤¤¤
  29. [Efrain][SUSP PATH] Z Cinema.lnk : C:\Users\Efrain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Z Cinema.lnk @C:\Users\Efrain\AppData\Roaming\Microsoft\Installer\{3D1A8E16-10A6-43E0-90BE-0A0474A637A7}\NewShortcut1_3D1A8E1610A643E090BE0A0474A637A7.exe /Minimize [-][-] -> DELETED
  30.  
  31. ¤¤¤ Web browsers : 0 ¤¤¤
  32.  
  33. ¤¤¤ Browser Addons : 0 ¤¤¤
  34.  
  35. ¤¤¤ Particular Files / Folders: ¤¤¤
  36.  
  37. ¤¤¤ Driver : [LOADED] ¤¤¤
  38.  
  39. ¤¤¤ External Hives: ¤¤¤
  40.  
  41. ¤¤¤ Infection : ¤¤¤
  42.  
  43. ¤¤¤ HOSTS File: ¤¤¤
  44. --> %SystemRoot%\System32\drivers\etc\hosts
  45.  
  46.  
  47.  
  48.  
  49. ¤¤¤ MBR Check: ¤¤¤
  50.  
  51. +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ SCSI) SAMSUNG HD501LJ +++++
  52. --- User ---
  53. [MBR] 9258928d86c154b032c6de048637f7a6
  54. [BSP] ceb84c3e7b096f62a58a22cb4210973b : Windows 7/8 MBR Code
  55. Partition table:
  56. 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 464912 Mo
  57. 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 952140420 | Size: 12025 Mo
  58. User = LL1 ... OK!
  59. User = LL2 ... OK!
  60.  
  61. +++++ PhysicalDrive1: (\\.\PHYSICALDRIVE2 @ USB) WDC WD50 00BEVT-22ZAT0 USB Device +++++
  62. --- User ---
  63. [MBR] 2e01f508988c154e1f0aa2e9e3159799
  64. [BSP] 6905deb1716f55e21b73b826eda7a4cc : Windows XP MBR Code
  65. Partition table:
  66. 0 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 16065 | Size: 476929 Mo
  67. User = LL1 ... OK!
  68. Error reading LL2 MBR! ([0x32] The request is not supported. )
  69.  
  70. Finished : << RKreport[0]_D_03142014_053643.txt >>
  71. RKreport[0]_S_03142014_053524.txt
Advertisement
Add Comment
Please, Sign In to add comment