Advertisement
silentcommit

roguekiller log

Sep 10th, 2013
105
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.98 KB | None | 0 0
  1. RogueKiller V8.6.10 _x64_ [Sep 9 2013] by Tigzy
  2. mail : tigzyRK<at>gmail<dot>com
  3. Feedback : http://www.adlice.com/forum/
  4. Website : http://www.adlice.com/softwares/roguekiller/
  5. Blog : http://tigzyrk.blogspot.com/
  6.  
  7. Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
  8. Started in : Normal mode
  9. User : Carrie [Admin rights]
  10. Mode : Scan -- Date : 09/10/2013 19:12:04
  11. | ARK || FAK || MBR |
  12.  
  13. ¤¤¤ Bad processes : 0 ¤¤¤
  14.  
  15. ¤¤¤ Registry Entries : 7 ¤¤¤
  16. [HJ POL] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
  17. [HJ POL] HKLM\[...]\System : EnableLUA (0) -> FOUND
  18. [HJ POL] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
  19. [HJ POL] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> FOUND
  20. [HJ SMENU] HKCU\[...]\Advanced : Start_ShowRun (0) -> FOUND
  21. [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
  22. [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
  23.  
  24. ¤¤¤ Scheduled tasks : 15 ¤¤¤
  25. [V1][SUSP PATH] Arcadesafari.job : C:\Users\Carrie\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe [7] -> FOUND
  26. [V1][SUSP PATH] AllmyappsUpdateTask.job : C:\Users\Carrie\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe - check startup [7][x] -> FOUND
  27. [V2][SUSP PATH] AllmyappsUpdateTask : C:\Users\Carrie\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe - check startup [7][x] -> FOUND
  28. [V2][SUSP PATH] Arcadesafari : C:\Users\Carrie\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe [7] -> FOUND
  29. [V2][SUSP PATH] {077DF77B-3544-4BC4-851A-184819D868F2} : C:\Users\Carrie\Desktop\safe.exe [-] -> FOUND
  30. [V2][SUSP PATH] {0E8750C1-1D26-4E71-9C42-A85FCF43E0EF} : C:\Users\Carrie\Desktop\ie.exe [x] -> FOUND
  31. [V2][SUSP PATH] {14BAEAF4-9954-4703-93BA-8A328CDC7898} : C:\Users\Carrie\Desktop\ie.exe [x] -> FOUND
  32. [V2][SUSP PATH] {2D31A804-F9FF-4C63-AD61-7A26008A1C8E} : C:\Users\Carrie\Desktop\safe.exe [-] -> FOUND
  33. [V2][SUSP PATH] {5C944199-76A3-4989-B558-4926FA7D2E8B} : C:\Users\Carrie\Desktop\safe.exe [-] -> FOUND
  34. [V2][SUSP PATH] {781DA757-B430-43DE-9F6F-C2FC08BEA2FE} : C:\Users\Carrie\Desktop\ie.exe [x] -> FOUND
  35. [V2][SUSP PATH] {7EFDA9EA-9287-42ED-9A0D-9FD12E909264} : C:\Users\Carrie\Desktop\safe.exe [-] -> FOUND
  36. [V2][SUSP PATH] {8D2C11BA-8E55-4483-87B7-71CE7195A128} : C:\Users\Carrie\Desktop\safe.exe [-] -> FOUND
  37. [V2][SUSP PATH] {C3F5A4FC-0E7A-40DD-98BA-7782EAF94EBF} : C:\Users\Carrie\Desktop\ie.exe [x] -> FOUND
  38. [V2][SUSP PATH] {E90DEAF8-3137-44AA-9165-31B4CD3D2637} : C:\Users\Carrie\Desktop\safe.exe [-] -> FOUND
  39. [V2][SUSP PATH] {F226BD7F-F697-4C0C-BB59-3C661F80D2B2} : C:\Users\Carrie\Desktop\ie.exe [x] -> FOUND
  40.  
  41. ¤¤¤ Startup Entries : 0 ¤¤¤
  42.  
  43. ¤¤¤ Web browsers : 0 ¤¤¤
  44.  
  45. ¤¤¤ Particular Files / Folders: ¤¤¤
  46.  
  47. ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
  48.  
  49. ¤¤¤ External Hives: ¤¤¤
  50.  
  51. ¤¤¤ Infection : ¤¤¤
  52.  
  53. ¤¤¤ HOSTS File: ¤¤¤
  54. --> %SystemRoot%\System32\drivers\etc\hosts
  55.  
  56.  
  57. 127.0.0.1 www.007guard.com
  58. 127.0.0.1 007guard.com
  59. 127.0.0.1 008i.com
  60. 127.0.0.1 www.008k.com
  61. 127.0.0.1 008k.com
  62. 127.0.0.1 www.00hq.com
  63. 127.0.0.1 00hq.com
  64. 127.0.0.1 010402.com
  65. 127.0.0.1 www.032439.com
  66. 127.0.0.1 032439.com
  67. 127.0.0.1 www.0scan.com
  68. 127.0.0.1 0scan.com
  69. 127.0.0.1 www.1000gratisproben.com
  70. 127.0.0.1 1000gratisproben.com
  71. 127.0.0.1 1001namen.com
  72. 127.0.0.1 www.1001namen.com
  73. 127.0.0.1 100888290cs.com
  74. 127.0.0.1 www.100888290cs.com
  75. 127.0.0.1 www.100sexlinks.com
  76. 127.0.0.1 100sexlinks.com
  77. [...]
  78.  
  79.  
  80. ¤¤¤ MBR Check: ¤¤¤
  81.  
  82. +++++ PhysicalDrive0: TOSHIBA MK3265GSXN SATA Disk Device +++++
  83. --- User ---
  84. [MBR] ccf60736590eef2cfd6a7aa695256f66
  85. [BSP] 66145dbfca0f0410ab0749a594446f83 : Windows Vista MBR Code
  86. Partition table:
  87. 0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
  88. 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 292137 Mo
  89. 2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 601370624 | Size: 11607 Mo
  90. User = LL1 ... OK!
  91. User = LL2 ... OK!
  92.  
  93. Finished : << RKreport[0]_S_09102013_191204.txt >>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement