Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- RogueKiller V8.6.11 [Sep 11 2013] by Tigzy
- mail : tigzyRK<at>gmail<dot>com
- Feedback : http://www.adlice.com/forum/
- Website : http://www.adlice.com/softwares/roguekiller/
- Blog : http://tigzyrk.blogspot.com/
- Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
- Started in : Normal mode
- User : Camilla [Admin rights]
- Mode : Scan -- Date : 09/14/2013 15:17:35
- | ARK || FAK || MBR |
- ¤¤¤ Bad processes : 1 ¤¤¤
- [ZeroAccess][SERVICE] ???etadpug -- "C:\Program Files (x86)\Google\Desktop\Install\{17b72e44-ea30-50a1-d367-082e40143dc5}\ \...\???ﯹ๛\{17b72e44-ea30-50a1-d367-082e40143dc5}\GoogleUpdate.exe" < [x] -> STOPPED
- ¤¤¤ Registry Entries : 16 ¤¤¤
- [SERVICE][ZeroAccess] HKLM\[...]\CCSet\[...]\Services : ???etadpug (C:\Windows\system32\???etadpug.sys [x]) -> FOUND
- [SERVICE][ZeroAccess] HKLM\[...]\CS001\[...]\Services : ???etadpug (C:\Windows\system32\???etadpug.sys [x]) -> FOUND
- [SERVICE][ZeroAccess] HKLM\[...]\CS002\[...]\Services : ???etadpug (C:\Windows\system32\???etadpug.sys [x]) -> FOUND
- [HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
- [HJ POL] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
- [HJ POL] HKLM\[...]\System : EnableLUA (0) -> FOUND
- [HJ POL] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
- [HJ POL] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> FOUND
- [HJ SMENU] HKCU\[...]\Advanced : Start_ShowUser (0) -> FOUND
- [HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
- [HJ SMENU] HKCU\[...]\Advanced : Start_ShowHelp (0) -> FOUND
- [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
- [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
- [HID SVC][Hidden from API] HKLM\[...]\CCSet\[...]\Services : . e () -> FOUND
- [HID SVC][Hidden from API] HKLM\[...]\CS001\[...]\Services : . e () -> FOUND
- [HID SVC][Hidden from API] HKLM\[...]\CS002\[...]\Services : . e () -> FOUND
- ¤¤¤ Scheduled tasks : 0 ¤¤¤
- ¤¤¤ Startup Entries : 0 ¤¤¤
- ¤¤¤ Web browsers : 0 ¤¤¤
- ¤¤¤ Particular Files / Folders: ¤¤¤
- [ZeroAccess][Folder] Install : C:\Users\Camilla\AppData\Local\Google\Desktop\Install [-] --> FOUND
- ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
- ¤¤¤ External Hives: ¤¤¤
- ¤¤¤ Infection : ZeroAccess ¤¤¤
- ¤¤¤ HOSTS File: ¤¤¤
- --> %SystemRoot%\System32\drivers\etc\hosts
- 127.0.0.1 activate.adobe.com
- 127.0.0.1 practivate.adobe.com
- 127.0.0.1 ereg.adobe.com
- 127.0.0.1 activate.wip3.adobe.com
- 127.0.0.1 wip3.adobe.com
- 127.0.0.1 3dns-3.adobe.com
- 127.0.0.1 3dns-2.adobe.com
- 127.0.0.1 adobe-dns.adobe.com
- 127.0.0.1 adobe-dns-2.adobe.com
- 127.0.0.1 adobe-dns-3.adobe.com
- 127.0.0.1 ereg.wip3.adobe.com
- 127.0.0.1 activate-sea.adobe.com
- 127.0.0.1 wwis-dubc1-vip60.adobe.com
- 127.0.0.1 activate-sjc0.adobe.com
- 127.0.0.1 practivate.adobe.com
- 127.0.0.1 ereg.adobe.com
- 127.0.0.1 activate.wip3.adobe.com
- 127.0.0.1 wip3.adobe.com
- 127.0.0.1 3dns-3.adobe.com
- 127.0.0.1 3dns-2.adobe.com
- [...]
- ¤¤¤ MBR Check: ¤¤¤
- +++++ PhysicalDrive0: FUJITSU MJA2320BH G2 ATA Device +++++
- --- User ---
- [MBR] 93feb000db0554a00a3421b15dcdb0d6
- [BSP] 15acce822de47f8bd123cf5c652a0d29 : Windows Vista/7/8 MBR Code
- Partition table:
- 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
- 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 289895 Mo
- 2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 594114560 | Size: 15046 Mo
- 3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 624928768 | Size: 103 Mo
- User = LL1 ... OK!
- User = LL2 ... OK!
- Finished : << RKreport[0]_S_09142013_151735.txt >>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement