Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- RogueKiller V8.7.2 _x64_ [Oct 3 2013] by Tigzy
- mail : tigzyRK<at>gmail<dot>com
- Feedback : http://www.adlice.com/forum/
- Website : http://www.adlice.com/softwares/roguekiller/
- Blog : http://tigzyrk.blogspot.com/
- Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
- Started in : Normal mode
- User : jdudley [Admin rights]
- Mode : Scan -- Date : 10/14/2013 12:35:28
- | ARK || FAK || MBR |
- ¤¤¤ Bad processes : 0 ¤¤¤
- ¤¤¤ Registry Entries : 34 ¤¤¤
- [HJ TASKMAN] HKLM\[...]\Wow6432Node\[...]\Winlogon : TaskMan () -> FOUND
- [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (192.168.29.200:80) -> FOUND
- [DNS][PUM] HKLM\[...]\CCSet\[...]\{066DB5DA-8AC1-4487-870D-9DAA15033CA9} : NameServer (82.132.254.2 82.132.254.3) -> FOUND
- [DNS][PUM] HKLM\[...]\CCSet\[...]\{6D3DFB6A-4EFF-4B63-BB9D-F8DD1A38971D} : NameServer (10.50.30.67) -> FOUND
- [DNS][PUM] HKLM\[...]\CCSet\[...]\{A5D43338-7E3D-4211-B877-116F2113B7DE} : NameServer (10.50.30.67) -> FOUND
- [DNS][PUM] HKLM\[...]\CCSet\[...]\{BE289F84-BC28-4411-831E-2139F3E68D2C} : NameServer (10.50.30.67) -> FOUND
- [DNS][PUM] HKLM\[...]\CS001\[...]\{066DB5DA-8AC1-4487-870D-9DAA15033CA9} : NameServer (82.132.254.2 82.132.254.3) -> FOUND
- [DNS][PUM] HKLM\[...]\CS001\[...]\{6D3DFB6A-4EFF-4B63-BB9D-F8DD1A38971D} : NameServer (10.50.30.67) -> FOUND
- [DNS][PUM] HKLM\[...]\CS001\[...]\{A5D43338-7E3D-4211-B877-116F2113B7DE} : NameServer (10.50.30.67) -> FOUND
- [DNS][PUM] HKLM\[...]\CS001\[...]\{BE289F84-BC28-4411-831E-2139F3E68D2C} : NameServer (10.50.30.67) -> FOUND
- [DNS][PUM] HKLM\[...]\CS002\[...]\{066DB5DA-8AC1-4487-870D-9DAA15033CA9} : NameServer (82.132.254.2 82.132.254.3) -> FOUND
- [DNS][PUM] HKLM\[...]\CS002\[...]\{6D3DFB6A-4EFF-4B63-BB9D-F8DD1A38971D} : NameServer (10.50.30.67) -> FOUND
- [DNS][PUM] HKLM\[...]\CS002\[...]\{A5D43338-7E3D-4211-B877-116F2113B7DE} : NameServer (10.50.30.67) -> FOUND
- [DNS][PUM] HKLM\[...]\CS002\[...]\{BE289F84-BC28-4411-831E-2139F3E68D2C} : NameServer (10.50.30.67) -> FOUND
- [HJ POL][PUM] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND
- [HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
- [HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
- [HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> FOUND
- [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableTaskMgr (0) -> FOUND
- [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> FOUND
- [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
- [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> FOUND
- [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
- [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_TrackProgs (0) -> FOUND
- [HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
- [HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
- [HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
- [HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
- [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
- [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
- [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\jdudley\AppData\Local\{cf77ec27-39e7-8307-93c7-4ae7e2e77130}\n. [x]) -> FOUND
- [HJ DLL][SUSP PATH] HKLM\[...]\CCSet\[...]\Parameters : ServiceDll (C:\PROGRA~3\j60lcbj4.pzz [x]) -> FOUND
- [HJ DLL][SUSP PATH] HKLM\[...]\CS001\[...]\Parameters : ServiceDll (C:\PROGRA~3\j60lcbj4.pzz [x]) -> FOUND
- [HJ DLL][SUSP PATH] HKLM\[...]\CS002\[...]\Parameters : ServiceDll (C:\PROGRA~3\j60lcbj4.pzz [x]) -> FOUND
- ¤¤¤ Scheduled tasks : 0 ¤¤¤
- ¤¤¤ Startup Entries : 0 ¤¤¤
- ¤¤¤ Web browsers : 0 ¤¤¤
- ¤¤¤ Particular Files / Folders: ¤¤¤
- ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
- ¤¤¤ External Hives: ¤¤¤
- ¤¤¤ Infection : ¤¤¤
- ¤¤¤ HOSTS File: ¤¤¤
- --> %SystemRoot%\System32\drivers\etc\hosts
- 65.170.40.142 notes.abinitio.com notes
- 65.170.40.143 estes.abinitio.com estes
- 192.168.117.129 abdemo
- ¤¤¤ MBR Check: ¤¤¤
- +++++ PhysicalDrive0: ( @ ) - +++++
- --- User ---
- [MBR] 6b7df0dab00bfa34472e2b26835888df
- [BSP] edef1bf55c0edd542455e2050c9692c8 : Lenovo MBR Code
- Partition table:
- 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 1853 Mo
- 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 3795120 | Size: 475084 Mo
- User = LL1 ... OK!
- User = LL2 ... OK!
- Finished : << RKreport[0]_S_10142013_123528.txt >>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement