SHOW:
|
|
- or go back to the newest paste.
1 | RogueKiller V8.7.8 [Nov 14 2013] by Tigzy | |
2 | mail : tigzyRK<at>gmail<dot>com | |
3 | Feedback : http://www.adlice.com/forum/ | |
4 | Website : http://www.adlice.com/softwares/roguekiller/ | |
5 | Blog : http://tigzyrk.blogspot.com/ | |
6 | ||
7 | Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version | |
8 | Started in : Normal mode | |
9 | User : Marion [Admin rights] | |
10 | Mode : Scan -- Date : 11/14/2013 13:12:38 | |
11 | | ARK || FAK || MBR | | |
12 | ||
13 | ¤¤¤ Bad processes : 0 ¤¤¤ | |
14 | ||
15 | ¤¤¤ Registry Entries : 7 ¤¤¤ | |
16 | [RUN][SUSP PATH] HKUS\S-1-5-21-1013639583-4134777893-1337409647-1005\[...]\Run : iTunes Sync ("C:\Users\Marion\AppData\Local\Apps\2.0\H0T3JGL3.JGK\BMB4RVJK.XV3\itun..tion_e05fb8e279c30af8_0001.0000_76d6a1fc3fa61adf\iTunesSync.exe" [x]) -> FOUND | |
17 | [HJ POL][PUM] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND | |
18 | [HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND | |
19 | [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableTaskMgr (0) -> FOUND | |
20 | [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> FOUND | |
21 | [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND | |
22 | [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND | |
23 | ||
24 | ¤¤¤ Scheduled tasks : 0 ¤¤¤ | |
25 | ||
26 | ¤¤¤ Startup Entries : 0 ¤¤¤ | |
27 | ||
28 | ¤¤¤ Web browsers : 0 ¤¤¤ | |
29 | ||
30 | ¤¤¤ Particular Files / Folders: ¤¤¤ | |
31 | ||
32 | ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤ | |
33 | ||
34 | ¤¤¤ External Hives: ¤¤¤ | |
35 | ||
36 | ¤¤¤ Infection : ¤¤¤ | |
37 | ||
38 | ¤¤¤ HOSTS File: ¤¤¤ | |
39 | --> %SystemRoot%\System32\drivers\etc\hosts | |
40 | ||
41 | ||
42 | ||
43 | ||
44 | ¤¤¤ MBR Check: ¤¤¤ | |
45 | ||
46 | +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Disk drive +++++ | |
47 | --- User --- | |
48 | [MBR] 84aaa0738bdaffb6f12d20e4bbcb351b | |
49 | [BSP] 4256c9c3f66f877af498ae4be7546dab : Windows 7/8 MBR Code | |
50 | Partition table: | |
51 | 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo | |
52 | 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 610378 Mo | |
53 | User = LL1 ... OK! | |
54 | User = LL2 ... OK! | |
55 | ||
56 | Finished : << RKreport[0]_S_11142013_131238.txt >> |