Advertisement
Guest User

Untitled

a guest
Apr 20th, 2014
129
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.71 KB | None | 0 0
  1. RogueKiller V8.8.15 _x64_ [Mar 27 2014] by Adlice Software
  2. mail : http://www.adlice.com/contact/
  3. Feedback : http://forum.adlice.com
  4. Website : http://www.adlice.com/softwares/roguekiller/
  5. Blog : http://www.adlice.com
  6.  
  7. Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
  8. Started in : Normal mode
  9. User : Druback [Admin rights]
  10. Mode : Scan -- Date : 04/20/2014 12:24:20
  11. | ARK || FAK || MBR |
  12.  
  13. ¤¤¤ Bad processes : 1 ¤¤¤
  14. [SUSP PATH][DLL] explorer.exe -- C:\Users\Druback\AppData\Local\Temp\TeamViewer\Version8\tv_x64.dll [x] -> UNLOADED
  15.  
  16. ¤¤¤ Registry Entries : 3 ¤¤¤
  17. [HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
  18. [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
  19. [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
  20.  
  21. ¤¤¤ Scheduled tasks : 0 ¤¤¤
  22.  
  23. ¤¤¤ Startup Entries : 0 ¤¤¤
  24.  
  25. ¤¤¤ Web browsers : 0 ¤¤¤
  26.  
  27. ¤¤¤ Browser Addons : 0 ¤¤¤
  28.  
  29. ¤¤¤ Particular Files / Folders: ¤¤¤
  30.  
  31. ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
  32. [Address] IAT @iexplore.exe (GetProcAddress) : KERNEL32.dll -> HOOKED (C:\Program Files\Internet Explorer\IEShims.dll @ 0xF0D93330)
  33. [Address] IAT @iexplore.exe (StrStrIW) : api-ms-win-downlevel-shlwapi-l1-1-0.dll -> HOOKED (C:\Windows\system32\SHLWAPI.dll @ 0xFDC1FB70)
  34. [Address] IAT @iexplore.exe (GetProcAddress) : KERNEL32.dll -> HOOKED (C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6DE613DD)
  35. [Address] IAT @iexplore.exe (StrStrIW) : api-ms-win-downlevel-shlwapi-l1-1-0.dll -> HOOKED (C:\Windows\syswow64\shlwapi.DLL @ 0x75E846E9)
  36.  
  37. ¤¤¤ External Hives: ¤¤¤
  38.  
  39. ¤¤¤ Infection : ¤¤¤
  40.  
  41. ¤¤¤ HOSTS File: ¤¤¤
  42. --> %SystemRoot%\System32\drivers\etc\hosts
  43.  
  44.  
  45.  
  46.  
  47. ¤¤¤ MBR Check: ¤¤¤
  48.  
  49. +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS547564A9E384 +++++
  50. --- User ---
  51. [MBR] c77650dadbdd74338a079796ec001b93
  52. [BSP] 139f9342507d5f69d78b8d4d1cc64ad7 : Windows 7/8 MBR Code
  53. Partition table:
  54. 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 MB
  55. 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 595763 MB
  56. 2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1220532224 | Size: 14413 MB
  57. 3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 1250050048 | Size: 103 MB
  58. User = LL1 ... OK!
  59. User != LL2 ... KO!
  60. --- LL2 ---
  61. [MBR] e9db50b585bb6053fe928f1845a2075a
  62. [BSP] 139f9342507d5f69d78b8d4d1cc64ad7 : Windows 7/8 MBR Code
  63. Partition table:
  64. 0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 77824 MB
  65. 1 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 159793152 | Size: 400 MB
  66.  
  67. Finished : << RKreport[0]_S_04202014_122420.txt >>
  68. RKreport[0]_S_04122014_173543.txt
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement