Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- RogueKiller V8.8.11 [Mar 14 2014] by Adlice Software
- mail : http://www.adlice.com/contact/
- Feedback : http://forum.adlice.com
- Website : http://www.adlice.com/softwares/roguekiller/
- Blog : http://www.adlice.com
- Operating System : Windows 7 (6.1.7600 ) 32 bits version
- Started in : Normal mode
- User : Siyar [Admin rights]
- Mode : Scan -- Date : 03/14/2014 16:34:31
- | ARK || FAK || MBR |
- ¤¤¤ Bad processes : 1 ¤¤¤
- [SUSP PATH][DLL] explorer.exe -- C:\Users\Siyar\AppData\Roaming\ICQM\ICQ\dll\mramenu.dll [x] -> UNLOADED
- ¤¤¤ Registry Entries : 6 ¤¤¤
- [RUN][SUSP PATH] HKCU\[...]\Run : AVG-Secure-Search-Update_0913b (C:\Users\Siyar\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 477528af873947d1976ed154d4c7221c-ace776aea56d0a0deac3e8203236c80400a0cf40 --CMPID 0913b [-][x][x]) -> FOUND
- [RUN][SUSP PATH] HKUS\S-1-5-21-4022737933-1016067012-279495612-1001\[...]\Run : AVG-Secure-Search-Update_0913b (C:\Users\Siyar\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 477528af873947d1976ed154d4c7221c-ace776aea56d0a0deac3e8203236c80400a0cf40 --CMPID 0913b [-][x][x]) -> FOUND
- [HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
- [HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> FOUND
- [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
- [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
- ¤¤¤ Scheduled tasks : 0 ¤¤¤
- ¤¤¤ Startup Entries : 0 ¤¤¤
- ¤¤¤ Web browsers : 0 ¤¤¤
- ¤¤¤ Browser Addons : 0 ¤¤¤
- ¤¤¤ Particular Files / Folders: ¤¤¤
- ¤¤¤ Driver : [LOADED] ¤¤¤
- [Inline] SSDT[50] : NtClose @ 0x8309279C -> HOOKED (Unknown @ 0x85A70DE0)
- [Address] Shadow SSDT[536] : NtUserSendInput -> HOOKED (C:\Windows\system32\drivers\EagleXNt.sys @ 0xA4198FC0)
- ¤¤¤ External Hives: ¤¤¤
- ¤¤¤ Infection : ¤¤¤
- ¤¤¤ HOSTS File: ¤¤¤
- --> %SystemRoot%\System32\drivers\etc\hosts
- ¤¤¤ MBR Check: ¤¤¤
- +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD5000AACS-00ZUB0 ATA Device +++++
- --- User ---
- [MBR] 4c5c5fcf7bba6971293adf1b0f715404
- [BSP] 15917931272a77cf13a97d97b053cf2e : MBR Code unknown
- Partition table:
- 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 476936 Mo
- User = LL1 ... OK!
- User = LL2 ... OK!
- Finished : << RKreport[0]_S_03142014_163431.txt >>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement