Advertisement
Guest User

Untitled

a guest
Sep 11th, 2014
35
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.78 KB | None | 0 0
  1. RogueKiller V9.2.10.0 (x64) [Jul 11 2014] by Adlice Software
  2. mail : http://www.adlice.com/contact/
  3. Feedback : http://forum.adlice.com
  4. Website : http://www.adlice.com/softwares/roguekiller/
  5. Blog : http://www.adlice.com
  6.  
  7. Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
  8. Started in : Normal mode
  9. User : Idan [Admin rights]
  10. Mode : Scan -- Date : 09/12/2014 00:57:00
  11.  
  12. ¤¤¤ Bad processes : 0 ¤¤¤
  13.  
  14. ¤¤¤ Registry Entries : 29 ¤¤¤
  15. [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mdareDriver_47 (\??\C:\Users\Idan\AppData\Local\Temp\FCPreScan\mdare64_47.sys) -> FOUND
  16. [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mdareDriver_47 (\??\C:\Users\Idan\AppData\Local\Temp\FCPreScan\mdare64_47.sys) -> FOUND
  17. [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mdareDriver_47 (\??\C:\Users\Idan\AppData\Local\Temp\FCPreScan\mdare64_47.sys) -> FOUND
  18. [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 192.117.235.235 62.219.186.7 -> FOUND
  19. [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.117.235.235 62.219.186.7 -> FOUND
  20. [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 192.117.235.235 62.219.186.7 -> FOUND
  21. [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7DE4A546-C524-4607-BDB6-4E458998E7B6} | DhcpNameServer : 192.117.235.235 62.219.186.7 -> FOUND
  22. [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{7DE4A546-C524-4607-BDB6-4E458998E7B6} | DhcpNameServer : 192.117.235.235 62.219.186.7 -> FOUND
  23. [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{7DE4A546-C524-4607-BDB6-4E458998E7B6} | DhcpNameServer : 192.117.235.235 62.219.186.7 -> FOUND
  24. [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> FOUND
  25. [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> FOUND
  26. [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | EnableLUA : 0 -> FOUND
  27. [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | EnableLUA : 0 -> FOUND
  28. [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> FOUND
  29. [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> FOUND
  30. [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> FOUND
  31. [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> FOUND
  32. [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> FOUND
  33. [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> FOUND
  34. [PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> FOUND
  35. [PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> FOUND
  36. [PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> FOUND
  37. [PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> FOUND
  38. [PUM.SearchPage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> FOUND
  39. [PUM.SearchPage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> FOUND
  40. [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-149788724-1810438044-2685332258-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> FOUND
  41. [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-149788724-1810438044-2685332258-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> FOUND
  42. [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> FOUND
  43. [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> FOUND
  44.  
  45. ¤¤¤ Scheduled tasks : 0 ¤¤¤
  46.  
  47. ¤¤¤ Files : 0 ¤¤¤
  48.  
  49. ¤¤¤ HOSTS File : 0 ¤¤¤
  50.  
  51. ¤¤¤ Antirootkit : 1 (Driver: LOADED) ¤¤¤
  52. [Filter(Kernel.Filter)] \Driver\atapi @ \Device\CdRom0 : \Driver\GEARAspiWDM @ Unknown (\??\C:\Windows\system32\drivers\VMkbd.sys)
  53.  
  54. ¤¤¤ Web browsers : 0 ¤¤¤
  55.  
  56. ¤¤¤ MBR Check : ¤¤¤
  57. +++++ PhysicalDrive0: SAMSUNG HD103SJ ATA Device +++++
  58. --- User ---
  59. [MBR] a65051ae701f95d8e1bb20681ad6a2b0
  60. [BSP] 69c8c1845cffecf9450576c8ab070c7c : Windows Vista/7/8 MBR Code
  61. Partition table:
  62. 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 953859 MB
  63. User = LL1 ... OK
  64. User = LL2 ... OK
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement