My first run of Rogue killer will do it one more time. Forgot to close everything.
RogueKiller V8.8.11 [Mar 14 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User : User [Admin rights]
Mode : Remove -- Date : 03/16/2014 17:44:38
| ARK || FAK || MBR |
¤¤¤ Bad processes : 4 ¤¤¤
[SUSP PATH] ouc.exe -- C:\ProgramData\MTN Online\OnlineUpdate\ouc.exe [7] -> KILLED [TermProc]
[SUSP PATH] TorchCrashHandler.exe -- C:\Users\User\AppData\Local\Torch\Update\TorchCrashHandler.exe [-] -> KILLED [TermProc]
[SUSP PATH] PC_173340.en_84.exe -- C:\Users\User\AppData\Roaming\PC-Gizmos\PC_173340.en_84.exe [-] -> KILLED [TermProc]
[SUSP PATH] Badoo.Desktop.exe -- C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7] -> KILLED [TermProc]
¤¤¤ Registry Entries : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : PC_GIZMOS ("C:\Users\User\AppData\Roaming\PC-Gizmos\PC_173340.en_84.exe" --update [-]) -> DELETED
[RUN][SUSP PATH] HKCU\[...]\Run : Badoo Desktop (C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7]) -> DELETED
[RUN][SUSP PATH] HKUS\S-1-5-21-2843941605-1469140519-1114756648-1000\[...]\Run : PC_GIZMOS ("C:\Users\User\AppData\Roaming\PC-Gizmos\PC_173340.en_84.exe" --update [-]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2843941605-1469140519-1114756648-1000\[...]\Run : Badoo Desktop (C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7]) -> [0x2] The system cannot find the file specified.
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[APPINIT][SUSP PATH] HKLM\[...]\Windows : AppInit_DLLs (c:\progra~2\bitguard\271769~1.27\{c16c1~1\bitguard.dll [x]) -> REPLACED ()
¤¤¤ Scheduled tasks : 7 ¤¤¤
[V1][SUSP PATH] Dealply.job : C:\Users\User\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE - /Check [x] -> DELETED
[V1][SUSP PATH] Digital Sites.job : C:\Users\User\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> DELETED
[V1][SUSP PATH] DSite.job : C:\Users\User\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE - /Check [x] -> DELETED
[V2][SUSP PATH] Dealply : C:\Users\User\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE - /Check [x] -> DELETED
[V2][SUSP PATH] Digital Sites : C:\Users\User\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> ERROR DELETING TASK
[V2][SUSP PATH] DSite : C:\Users\User\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE - /Check [x] -> ERROR DELETING TASK
[V2][SUSP PATH] DTReg : C:\Users\User\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe [x] -> DELETED
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Browser Addons : 1 ¤¤¤
[][PUP] Default : Torch Share
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
[Address] IRP[IRP_MJ_CREATE] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_CLOSE] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_DEVICE_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_POWER] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_SYSTEM_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_PNP] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : PUP ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) HITACHI HTS541680J9SA00 ATA Device +++++
--- User ---
[MBR] a59e707feda1465dff8f9f2f0696d50a
[BSP] acdc29e6e632166b38c4b02b556e2fa2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 356 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 731136 | Size: 75961 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_D_03162014_174437.txt >>
RKreport[0]_S_03162014_174226.txt
RogueKiller V8.8.11 [Mar 14 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User : User [Admin rights]
Mode : Remove -- Date : 03/16/2014 17:44:38
| ARK || FAK || MBR |
¤¤¤ Bad processes : 4 ¤¤¤
[SUSP PATH] ouc.exe -- C:\ProgramData\MTN Online\OnlineUpdate\ouc.exe [7] -> KILLED [TermProc]
[SUSP PATH] TorchCrashHandler.exe -- C:\Users\User\AppData\Local\Torch\Update\TorchCrashHandler.exe [-] -> KILLED [TermProc]
[SUSP PATH] PC_173340.en_84.exe -- C:\Users\User\AppData\Roaming\PC-Gizmos\PC_173340.en_84.exe [-] -> KILLED [TermProc]
[SUSP PATH] Badoo.Desktop.exe -- C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7] -> KILLED [TermProc]
¤¤¤ Registry Entries : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : PC_GIZMOS ("C:\Users\User\AppData\Roaming\PC-Gizmos\PC_173340.en_84.exe" --update [-]) -> DELETED
[RUN][SUSP PATH] HKCU\[...]\Run : Badoo Desktop (C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7]) -> DELETED
[RUN][SUSP PATH] HKUS\S-1-5-21-2843941605-1469140519-1114756648-1000\[...]\Run : PC_GIZMOS ("C:\Users\User\AppData\Roaming\PC-Gizmos\PC_173340.en_84.exe" --update [-]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2843941605-1469140519-1114756648-1000\[...]\Run : Badoo Desktop (C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7]) -> [0x2] The system cannot find the file specified.
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[APPINIT][SUSP PATH] HKLM\[...]\Windows : AppInit_DLLs (c:\progra~2\bitguard\271769~1.27\{c16c1~1\bitguard.dll [x]) -> REPLACED ()
¤¤¤ Scheduled tasks : 7 ¤¤¤
[V1][SUSP PATH] Dealply.job : C:\Users\User\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE - /Check [x] -> DELETED
[V1][SUSP PATH] Digital Sites.job : C:\Users\User\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> DELETED
[V1][SUSP PATH] DSite.job : C:\Users\User\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE - /Check [x] -> DELETED
[V2][SUSP PATH] Dealply : C:\Users\User\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE - /Check [x] -> DELETED
[V2][SUSP PATH] Digital Sites : C:\Users\User\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> ERROR DELETING TASK
[V2][SUSP PATH] DSite : C:\Users\User\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE - /Check [x] -> ERROR DELETING TASK
[V2][SUSP PATH] DTReg : C:\Users\User\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe [x] -> DELETED
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Browser Addons : 1 ¤¤¤
[][PUP] Default : Torch Share
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
[Address] IRP[IRP_MJ_CREATE] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_CLOSE] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_DEVICE_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_POWER] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_SYSTEM_CONTROL] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
[Address] IRP[IRP_MJ_PNP] : C:\Windows\System32\drivers\mountmgr.sys -> HOOKED (Unknown @ 0x856661F8)
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : PUP ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) HITACHI HTS541680J9SA00 ATA Device +++++
--- User ---
[MBR] a59e707feda1465dff8f9f2f0696d50a
[BSP] acdc29e6e632166b38c4b02b556e2fa2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 356 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 731136 | Size: 75961 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_D_03162014_174437.txt >>
RKreport[0]_S_03162014_174226.txt