RogueKiller 2
RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback :
https://www.techspot.com/downloads/5562-roguekiller.html
Website :
http://tigzy.geekstogo.com/roguekiller.php
Blog :
http://tigzyrk.blogspot.com/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : icevaner [Admin rights]
Mode : Remove -- Date : 05/12/2013 16:25:56
| ARK || FAK || MBR |
¤¤¤ Bad processes : 9 ¤¤¤
[BLACKLIST] BrowserProtect.exe -- C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[BLACKLIST] BrowserProtect.exe -- C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[SUSP PATH] yt2mp3_updater.exe -- C:\Users\icevaner\AppData\Local\Sevas-S\YouTube to MP3 Converter\yt2mp3_updater.exe [7] -> KILLED [TermProc]
[SUSP PATH] yt2mp3converter.exe -- C:\Users\icevaner\AppData\Local\Sevas-S\YouTube To MP3 Converter\yt2mp3converter.exe [7] -> KILLED [TermProc]
[SUSP PATH] SnapDo.exe -- C:\Users\icevaner\AppData\Local\Smartbar\Application\SnapDo.exe [7] -> KILLED [TermProc]
[RESIDUE] BrowserProtect.exe -- C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[RESIDUE] BrowserProtect.exe -- C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[RESIDUE] BrowserProtect.exe -- C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[RESIDUE] BrowserProtect.exe -- C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
¤¤¤ Registry Entries : 9 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Browser Infrastructure Helper (C:\Users\icevaner\AppData\Local\Smartbar\Application\SnapDo.exe startup) [7] -> DELETED
[Services][BLACKLIST] HKLM\[...]\ControlSet002\Services\BrowserProtect (C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe) [7] -> DELETED
[Services][BLACKLIST] HKLM\[...]\ControlSet003\Services\BrowserProtect (C:\ProgramData\BrowserProtect\2.6.1125.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe) [7] -> DELETED
[TASK][SUSP PATH] ROC_REG_JAN_DELETE.job : C:\ProgramData\AVG January 2013 Campaign\ROC.exe /DELETE_FROM_SYSTEM=1 [7] -> DELETED
[TASK][SUSP PATH] ROC_REG_JAN_DELETE : C:\ProgramData\AVG January 2013 Campaign\ROC.exe /DELETE_FROM_SYSTEM=1 [7] -> DELETED
[TASK][SUSP PATH] YouTubeToMP3ConverterUpdater : "C:\Users\icevaner\AppData\Local\Sevas-S\YouTube to MP3 Converter\yt2mp3_updater.exe" [7] -> DELETED
[HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> DELETED
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FILE] @ : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\@ [-] --> REMOVED AT REBOOT
[Del.Parent][FILE] 00000004.@ : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\U\00000004.@ [-] --> REMOVED
[Del.Parent][FILE] 00000008.@ : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\U\00000008.@ [-] --> REMOVED
[Del.Parent][FILE] 000000cb.@ : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\U\000000cb.@ [-] --> REMOVED
[Del.Parent][FILE] 80000000.@ : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\U\80000000.@ [-] --> REMOVED
[Del.Parent][FILE] 80000032.@ : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\U\80000032.@ [-] --> REMOVED
[Del.Parent][FILE] 80000064.@ : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\U\80000064.@ [-] --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\U --> REMOVED
[Del.Parent][FILE] 00000004.@ : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\L\00000004.@ [-] --> REMOVED
[Del.Parent][FILE] 201d3dde : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\L\201d3dde [-] --> REMOVED
[Del.Parent][FILE] 6715e287 : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\L\6715e287 [-] --> REMOVED
[Del.Parent][FILE] 76603ac3 : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\L\76603ac3 [-] --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\Windows\Installer\{6b99f8a4-e5ba-3bca-f880-9ecd4f6aaf64}\L --> REMOVED
[ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini [-] --> REMOVED AT REBOOT
[ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini [-] --> REMOVED AT REBOOT
[Susp.ASLR][FILE] services.exe : C:\Windows\system32\services.exe [-] --> REPLACED AT REBOOT (C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe)
¤¤¤ Driver : [NOT LOADED] ¤¤¤
¤¤¤ Infection : ZeroAccess ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST950032 5AS SATA Disk Device +++++
--- User ---
[MBR] da16576071d1155bdcd84e9aef6cb05c
[BSP] ad688a136b59c9b14840030d68dceb04 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 452394 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 926912512 | Size: 20282 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 968450048 | Size: 4063 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[2]_D_05122013_02d1625.txt >>
RKreport[1]_S_05122013_02d1558.txt ; RKreport[2]_D_05122013_02d1625.txt