Advertisement
Guest User

Untitled

a guest
Oct 17th, 2013
46
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.67 KB | None | 0 0
  1. RogueKiller V8.7.4 [Oct 16 2013] by Tigzy
  2. mail : tigzyRK<at>gmail<dot>com
  3. Feedback : http://www.adlice.com/forum/
  4. Website : http://www.adlice.com/softwares/roguekiller/
  5. Blog : http://tigzyrk.blogspot.com/
  6.  
  7. Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
  8. Started in : Normal mode
  9. User : Caleb's Computer [Admin rights]
  10. Mode : Scan -- Date : 10/17/2013 20:21:41
  11. | ARK || FAK || MBR |
  12.  
  13. ¤¤¤ Bad processes : 0 ¤¤¤
  14.  
  15. ¤¤¤ Registry Entries : 10 ¤¤¤
  16. [RUN][ZeroAccess] HKUS\.DEFAULT\[...]\Run : Google Update ("C:\Windows\system32\config\systemprofile\AppData\Local\Google\Desktop\Install\{510e5f06-3f78-7a78-850f-f1ce9435bd1e}\?��?��?��\?��?��?��\???ﯹ๛\{510e5f06-3f78-7a78-850f-f1ce9435bd1e}\GoogleUpdate.exe" >) -> FOUND
  17. [RUN][ZeroAccess] HKUS\S-1-5-18\[...]\Run : Google Update ("C:\Windows\system32\config\systemprofile\AppData\Local\Google\Desktop\Install\{510e5f06-3f78-7a78-850f-f1ce9435bd1e}\?��?��?��\?��?��?��\???ﯹ๛\{510e5f06-3f78-7a78-850f-f1ce9435bd1e}\GoogleUpdate.exe" >) -> FOUND
  18. [SHELL][SUSP PATH] HKCU\[...]\Winlogon : shell (C:\Users\Caleb's Computer\AppData\Roaming\dlc.xmm,explorer.exe [x][x][x]) -> FOUND
  19. [SHELL][SUSP PATH] HKUS\[...]\Winlogon : shell (C:\Users\Caleb's Computer\AppData\Roaming\dlc.xmm,explorer.exe [x][x][x]) -> FOUND
  20. [HJ POL][PUM] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND
  21. [HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
  22. [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableTaskMgr (0) -> FOUND
  23. [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> FOUND
  24. [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
  25. [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
  26.  
  27. ¤¤¤ Scheduled tasks : 0 ¤¤¤
  28.  
  29. ¤¤¤ Startup Entries : 0 ¤¤¤
  30.  
  31. ¤¤¤ Web browsers : 0 ¤¤¤
  32.  
  33. ¤¤¤ Particular Files / Folders: ¤¤¤
  34.  
  35. ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
  36.  
  37. ¤¤¤ External Hives: ¤¤¤
  38.  
  39. ¤¤¤ Infection : ZeroAccess ¤¤¤
  40.  
  41. ¤¤¤ HOSTS File: ¤¤¤
  42. --> %SystemRoot%\System32\drivers\etc\hosts
  43.  
  44.  
  45.  
  46.  
  47. ¤¤¤ MBR Check: ¤¤¤
  48.  
  49. +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standard disk drives) - WDC WD10EALX-229BA0 ATA Device +++++
  50. --- User ---
  51. [MBR] ddcf84195feb375c46a7653e9bca57ea
  52. [BSP] b7f1af624ca415852c3eb9ae77b37bea : Windows Vista MBR Code
  53. Partition table:
  54. 0 - [XXXXXX] FAT32 (0x1b) [HIDDEN!] Offset (sectors): 2048 | Size: 14524 Mo
  55. 1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 29747200 | Size: 939342 Mo
  56. User = LL1 ... OK!
  57. User = LL2 ... OK!
  58.  
  59. Finished : << RKreport[0]_S_10172013_202141.txt >>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement