SHOW:
|
|
- or go back to the newest paste.
| 1 | RogueKiller V8.7.8 [Nov 14 2013] by Tigzy | |
| 2 | mail : tigzyRK<at>gmail<dot>com | |
| 3 | Feedback : http://www.adlice.com/forum/ | |
| 4 | Website : http://www.adlice.com/softwares/roguekiller/ | |
| 5 | Blog : http://tigzyrk.blogspot.com/ | |
| 6 | ||
| 7 | Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version | |
| 8 | Started in : Normal mode | |
| 9 | User : Marion [Admin rights] | |
| 10 | Mode : Scan -- Date : 11/14/2013 13:12:38 | |
| 11 | | ARK || FAK || MBR | | |
| 12 | ||
| 13 | ¤¤¤ Bad processes : 0 ¤¤¤ | |
| 14 | ||
| 15 | ¤¤¤ Registry Entries : 7 ¤¤¤ | |
| 16 | [RUN][SUSP PATH] HKUS\S-1-5-21-1013639583-4134777893-1337409647-1005\[...]\Run : iTunes Sync ("C:\Users\Marion\AppData\Local\Apps\2.0\H0T3JGL3.JGK\BMB4RVJK.XV3\itun..tion_e05fb8e279c30af8_0001.0000_76d6a1fc3fa61adf\iTunesSync.exe" [x]) -> FOUND
| |
| 17 | [HJ POL][PUM] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND | |
| 18 | [HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND | |
| 19 | [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableTaskMgr (0) -> FOUND | |
| 20 | [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> FOUND | |
| 21 | [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
| |
| 22 | [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
| |
| 23 | ||
| 24 | ¤¤¤ Scheduled tasks : 0 ¤¤¤ | |
| 25 | ||
| 26 | ¤¤¤ Startup Entries : 0 ¤¤¤ | |
| 27 | ||
| 28 | ¤¤¤ Web browsers : 0 ¤¤¤ | |
| 29 | ||
| 30 | ¤¤¤ Particular Files / Folders: ¤¤¤ | |
| 31 | ||
| 32 | ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤ | |
| 33 | ||
| 34 | ¤¤¤ External Hives: ¤¤¤ | |
| 35 | ||
| 36 | ¤¤¤ Infection : ¤¤¤ | |
| 37 | ||
| 38 | ¤¤¤ HOSTS File: ¤¤¤ | |
| 39 | --> %SystemRoot%\System32\drivers\etc\hosts | |
| 40 | ||
| 41 | ||
| 42 | ||
| 43 | ||
| 44 | ¤¤¤ MBR Check: ¤¤¤ | |
| 45 | ||
| 46 | +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Disk drive +++++ | |
| 47 | --- User --- | |
| 48 | [MBR] 84aaa0738bdaffb6f12d20e4bbcb351b | |
| 49 | [BSP] 4256c9c3f66f877af498ae4be7546dab : Windows 7/8 MBR Code | |
| 50 | Partition table: | |
| 51 | 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo | |
| 52 | 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 610378 Mo | |
| 53 | User = LL1 ... OK! | |
| 54 | User = LL2 ... OK! | |
| 55 | ||
| 56 | Finished : << RKreport[0]_S_11142013_131238.txt >> |